CSC Cybersecurity Regulations & Legal Frameworks 3 — Questions and Answers
Question 1: A healthcare organization shares patient billing data with a third-party payment processor. Under HIPAA, the payment processor is classified as a:
- Covered entity
- Business associate (Correct answer)
- Hybrid entity
- Qualified service provider
Correct answer: Business associate
A third party that performs functions involving PHI on behalf of a covered entity is classified as a business associate and must sign a Business Associate Agreement (BAA).
Question 2: SOX Section 404 specifically requires management and external auditors to report on the effectiveness of:
- Cybersecurity incident response plans
- Internal controls over financial reporting (Correct answer)
- Data encryption standards
- Employee security awareness training
Correct answer: Internal controls over financial reporting
SOX Section 404 mandates that management assess and auditors attest to the effectiveness of internal controls over financial reporting (ICFR).
Question 3: Which GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Purpose limitation
The purpose limitation principle under GDPR Article 5(1)(b) states that personal data must be collected for specified, explicit, and legitimate purposes only.
Question 4: Under PCI DSS, which entities are required to undergo an annual on-site assessment by a Qualified Security Assessor (QSA)?
- All merchants processing credit card transactions
- Level 1 merchants processing over 6 million transactions annually (Correct answer)
- Any entity storing cardholder data
- Service providers handling any payment data
Correct answer: Level 1 merchants processing over 6 million transactions annually
PCI DSS Level 1 merchants, those processing more than 6 million card transactions per year, are required to undergo annual on-site QSA assessments.
Question 5: The Computer Fraud and Abuse Act (CFAA) defines 'protected computer' as:
- Any computer with encryption enabled
- Computers used exclusively by government agencies
- Any computer used in or affecting interstate commerce or communication (Correct answer)
- Computers certified under FIPS 140-2
Correct answer: Any computer used in or affecting interstate commerce or communication
The CFAA defines 'protected computer' broadly to include any computer used in or affecting interstate or foreign commerce or communication, covering virtually all internet-connected systems.
Question 6: Which regulation requires maritime and port facility operators to implement cybersecurity measures as part of facility security plans?
- NERC CIP
- MTSA (Maritime Transportation Security Act)
- TSA Security Directive
- Coast Guard NVIC 01-20 (Correct answer)
Correct answer: Coast Guard NVIC 01-20
Coast Guard Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on cybersecurity for maritime industry and incorporates NIST CSF requirements.
Question 7: Under California's CCPA, the right to opt-out allows consumers to direct businesses to stop:
- Collecting any personal information about them
- Selling their personal information to third parties (Correct answer)
- Using their data for internal analytics
- Retaining their data beyond 12 months
Correct answer: Selling their personal information to third parties
CCPA's right to opt-out specifically allows consumers to direct businesses to stop selling their personal information to third parties.
A healthcare organization shares patient billing data with a third-party payment processor.
Under HIPAA, the payment processor is classified as a: