CSL CSL Corporate Liability & Risk Management 2 — Questions and Answers
Question 1: Under the Gramm-Leach-Bliley Act (GLBA), which rule specifically mandates that financial institutions implement a written information security program?
- Privacy Rule
- Safeguards Rule (Correct answer)
- Pretexting Rule
- Disposal Rule
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program.
Question 2: Under HIPAA, which covered entity bears primary liability when a business associate suffers a data breach?
- Only the business associate bears liability
- Only the covered entity bears liability
- Both can face independent liability to HHS (Correct answer)
- Liability shifts entirely to the business associate under the BAA
Correct answer: Both can face independent liability to HHS
The HITECH Act amendments made business associates directly liable to HHS for HIPAA violations, with covered entities also potentially liable for inadequate oversight.
Question 3: What is the maximum civil monetary penalty per violation category under HIPAA for willful neglect that is not corrected?
- $10,000
- $50,000
- $100,000
- $1.9 million (Correct answer)
Correct answer: $1.9 million
HIPAA's tiered penalty structure imposes up to $1.9 million per violation category per calendar year for willful neglect that is not corrected.
Question 4: Which concept in corporate cybersecurity law refers to the baseline security practices that a reasonable company in a given industry should implement?
- Industry standard of care (Correct answer)
- Minimum viable security
- Safe harbor baseline
- Regulatory floor
Correct answer: Industry standard of care
The industry standard of care sets the benchmark for negligence claims by measuring a company's security practices against what is reasonable for its industry.
Question 5: Under the Sarbanes-Oxley Act (SOX), cybersecurity controls on financial reporting systems are relevant primarily because:
- SOX directly mandates NIST-based cybersecurity controls
- Compromise of financial systems could affect the accuracy of certified financial statements (Correct answer)
- SOX requires annual penetration testing of all systems
- The SEC requires SOX certification of all IT staff
Correct answer: Compromise of financial systems could affect the accuracy of certified financial statements
SOX Sections 302 and 906 require CEO/CFO certification of financial statements, creating liability if inadequate IT security allows manipulation of financial data.
Question 6: A company suffers a breach due to a third-party vendor's insecure API. Under which legal theory is the company most likely to be liable to affected customers?
- Strict products liability
- Negligent selection and oversight of vendors (Correct answer)
- Vicarious liability only
- No liability since the vendor caused the breach
Correct answer: Negligent selection and oversight of vendors
Companies have a duty to exercise reasonable care in selecting and overseeing vendors with access to customer data, and negligent oversight can create direct liability.
Under the Gramm-Leach-Bliley Act (GLBA), which rule specifically mandates that financial institutions implement a written information security program?