CSC Regulatory Compliance & Legal Aspects 3 — Questions and Answers
Question 1: Which NIST publication provides the primary framework for federal agencies to manage information security risk under FISMA?
- NIST SP 800-53
- NIST SP 800-171
- NIST CSF 2.0
- NIST SP 800-37 (Correct answer)
Correct answer: NIST SP 800-37
NIST SP 800-37 describes the Risk Management Framework (RMF) process that federal agencies use to authorize and continuously monitor systems under FISMA.
Question 2: Under GDPR Article 83, what is the maximum fine for the most serious violations (Tier 2)?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €100 million or 10% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR Tier 2 violations carry fines up to €20 million or 4% of the undertaking's total worldwide annual turnover, whichever is higher.
Question 3: A healthcare organization's business associate suffers a breach affecting 600 patients. Which entity must notify HHS and the affected individuals under the HIPAA Breach Notification Rule?
- The business associate directly
- The covered entity (Correct answer)
- Both the covered entity and business associate must notify HHS independently
- The state attorney general
Correct answer: The covered entity
Under the HIPAA Breach Notification Rule, the covered entity is responsible for notifying individuals and HHS, though the business associate must notify the covered entity promptly.
Question 4: The 'right to be forgotten' under GDPR is formally known as which article right?
- Right of access (Article 15)
- Right to erasure (Article 17) (Correct answer)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
Correct answer: Right to erasure (Article 17)
GDPR Article 17 establishes the right to erasure, commonly called the 'right to be forgotten,' allowing individuals to request deletion of their personal data under certain conditions.
Question 5: Which compliance framework is specifically designed for cloud service providers handling US federal government data at the FedRAMP Moderate baseline?
- CMMC Level 2
- FedRAMP Moderate ATO (Correct answer)
- FISMA Moderate
- StateRAMP
Correct answer: FedRAMP Moderate ATO
FedRAMP Moderate Authorization to Operate (ATO) is the specific authorization cloud providers must obtain to host federal agency data classified at the moderate impact level.
Question 6: An attacker intercepts employee emails to gather intelligence before a breach. Which law primarily governs this interception of electronic communications?
- Computer Fraud and Abuse Act
- Wiretap Act (Title I of ECPA) (Correct answer)
- Stored Communications Act (Title II of ECPA)
- Identity Theft Enforcement and Restitution Act
Correct answer: Wiretap Act (Title I of ECPA)
The Wiretap Act prohibits intentional interception of wire, oral, or electronic communications in transit, making it the primary statute for real-time interception.
Question 7: A security consultant advises a client that their vulnerability disclosure program must include a 'safe harbor' provision. What is the primary legal purpose of this provision?
- To limit the consultant's liability for findings
- To protect good-faith security researchers from legal action under CFAA and DMCA (Correct answer)
- To comply with SEC disclosure requirements
- To establish chain of custody for forensic evidence
Correct answer: To protect good-faith security researchers from legal action under CFAA and DMCA
A safe harbor provision in a vulnerability disclosure policy assures good-faith researchers they will not face CFAA or DMCA prosecution for authorized security testing.
Which NIST publication provides the primary framework for federal agencies to manage information security risk under FISMA?