CSC Cybersecurity Regulations & Legal Frameworks 2 — Questions and Answers
Question 1: Under HIPAA, which entity is directly required to comply with the Security Rule?
- Any business that handles health data
- Covered entities and their business associates (Correct answer)
- Only hospitals and health insurance companies
- Federal agencies that process Medicare claims
Correct answer: Covered entities and their business associates
HIPAA's Security Rule applies to covered entities (healthcare providers, health plans, clearinghouses) and business associates who handle protected health information on their behalf.
Question 2: Which law establishes the federal framework for protecting consumer financial information and requires financial institutions to implement safeguards?
- Sarbanes-Oxley Act (SOX)
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Fair Credit Reporting Act (FCRA)
- Electronic Funds Transfer Act (EFTA)
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and protect sensitive consumer data.
Question 3: GDPR's 'right to erasure' (right to be forgotten) allows individuals to request deletion of their personal data EXCEPT when:
- The data was collected with explicit consent
- Processing is necessary for compliance with a legal obligation (Correct answer)
- The individual withdraws consent
- The data is no longer necessary for its original purpose
Correct answer: Processing is necessary for compliance with a legal obligation
GDPR permits refusal of erasure requests when processing is required to comply with a legal obligation under EU or member state law.
Question 4: Which federal agency enforces Section 5 of the FTC Act against unfair or deceptive cybersecurity practices by companies?
- Department of Homeland Security
- Securities and Exchange Commission
- Federal Trade Commission (Correct answer)
- National Institute of Standards and Technology
Correct answer: Federal Trade Commission
The FTC enforces Section 5 of the FTC Act, which prohibits unfair or deceptive practices including failing to implement reasonable data security measures.
Question 5: Under the Cybersecurity Information Sharing Act (CISA 2015), sharing cyber threat indicators with the federal government grants organizations:
- Immunity from antitrust liability only
- Full immunity from all civil and criminal liability
- Certain antitrust and liability protections with privacy scrubbing requirements (Correct answer)
- No legal protection but regulatory credit
Correct answer: Certain antitrust and liability protections with privacy scrubbing requirements
CISA 2015 provides liability protections for private entities sharing cyber threat indicators, but requires scrubbing personally identifiable information before sharing.
Question 6: New York's SHIELD Act primarily expands which existing state law?
- New York Financial Services Law
- New York data breach notification law (Correct answer)
- New York consumer protection statute
- New York banking regulations
Correct answer: New York data breach notification law
The SHIELD Act expanded New York's data breach notification law by broadening the definition of private information and adding reasonable cybersecurity requirements.
Question 7: Which international framework is specifically designed to address cybersecurity for industrial control systems (ICS) and critical infrastructure?
- ISO/IEC 27001
- IEC 62443 (Correct answer)
- COBIT 5
- NIST SP 800-53
Correct answer: IEC 62443
IEC 62443 is the international standard series specifically addressing cybersecurity for industrial automation and control systems (IACS).
Under HIPAA, which entity is directly required to comply with the Security Rule?