Identity and Access Management (IAM) Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity and Access Management (IAM) Compliance flashcards as text
What compliance consideration specifically applies to biometric authentication data under U.S. and international regulations?
Answer: Biometric data is classified as sensitive personal data under laws like GDPR and Illinois BIPA, requiring consent, secure storage, and breach notification
Biometric data is immutable and uniquely identifies individuals, making it highly sensitive under GDPR, Illinois BIPA, and similar laws that require explicit consent, secure handling, and mandatory breach notification.
Why do service accounts require special IAM compliance attention in an organization?
Answer: Service accounts are non-human accounts used by applications with often-elevated privileges that lack standard interactive controls like password rotation
Service accounts run automated processes with elevated privileges, rarely rotate credentials interactively, and are high-value attack targets, requiring special monitoring, vaulting, and compliance controls.
Under SOX compliance, what specific IAM control is required for access to financial reporting systems?
Answer: Separation of duties and access controls preventing unauthorized modification of financial reporting data
SOX Section 404 requires documented internal controls over financial reporting, including separation of duties and access restrictions that prevent unauthorized users from altering financial data.
What is an access certification (recertification) campaign?
Answer: A periodic review process where managers formally attest to the appropriateness of their employees' current access rights
Access certification is a formal compliance process where data owners and managers review, approve, or revoke existing user access rights to enforce least privilege and document accountability.
What is the compliance-recommended approach to managing access for contractors and temporary workers?
Answer: Provide time-limited accounts scoped to specific project needs with automatic expiration dates
Contractors should receive accounts with access strictly scoped to their engagement and configured to expire automatically, applying least privilege and eliminating residual access after their engagement ends.
Which NIST Special Publication provides the federal standard for digital identity, authentication levels, and identity lifecycle management?
Answer: NIST SP 800-63 (Digital Identity Guidelines)
NIST SP 800-63 establishes identity assurance levels, authentication assurance levels, and federation assurance levels, serving as the authoritative federal guidance for digital identity programs.
What is deprovisioning and why is timely deprovisioning a critical compliance requirement?
Answer: Promptly revoking a departed or role-changed employee's access rights to prevent unauthorized access
Deprovisioning is the immediate revocation of access upon termination or role change; delayed deprovisioning is a common audit finding and violates least privilege requirements under PCI DSS, HIPAA, and SOX.