CSL CSL Government & Critical Infrastructure Security Law 1 — Questions and Answers
Question 1: Which U.S. federal agency has the primary civilian cybersecurity mission for protecting critical infrastructure under the Cybersecurity and Infrastructure Security Agency Act of 2018?
- NSA
- FBI
- CISA (Correct answer)
- DHS Office of Intelligence
Correct answer: CISA
CISA was established as the nation's cyber defense agency with responsibility for protecting federal civilian networks and coordinating critical infrastructure security.
Question 2: Presidential Policy Directive 21 (PPD-21) designates how many critical infrastructure sectors in the United States?
- 10 sectors
- 14 sectors
- 16 sectors (Correct answer)
- 20 sectors
Correct answer: 16 sectors
PPD-21 identifies 16 critical infrastructure sectors whose disruption would have a debilitating effect on national security, economic security, or public health and safety.
Question 3: What law requires federal agencies to implement a risk-based cybersecurity program based on the NIST Cybersecurity Framework and mandates annual security assessments?
- Federal Information Security Management Act (FISMA) (Correct answer)
- Cybersecurity Enhancement Act
- Federal Cybersecurity Risk Determination Act
- National Cybersecurity Protection Act
Correct answer: Federal Information Security Management Act (FISMA)
FISMA, as modernized in 2014, requires federal agencies to develop, document, and implement agency-wide information security programs and report to Congress annually.
Question 4: The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022 requires critical infrastructure entities to report covered cyber incidents to CISA within:
- 6 hours
- 24 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
CIRCIA requires covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
Question 5: Which Executive Order significantly strengthened U.S. federal cybersecurity requirements following the SolarWinds attack, mandating zero trust architecture and software supply chain security?
- Executive Order 13636 (2013)
- Executive Order 13800 (2017)
- Executive Order 14028 (2021) (Correct answer)
- Executive Order 14110 (2023)
Correct answer: Executive Order 14028 (2021)
EO 14028, 'Improving the Nation's Cybersecurity,' issued in May 2021, mandated zero trust architecture, enhanced logging, software bill of materials (SBOMs), and incident response improvements.
Question 6: Under the National Security Act and related authorities, which body coordinates national-level intelligence on cyber threats and integrates cybersecurity with national security?
- CISA alone
- NSC Cybersecurity Directorate and ONCD (Correct answer)
- FBI Cyber Division only
- NIST Cybersecurity Center
Correct answer: NSC Cybersecurity Directorate and ONCD
The National Security Council's Cyber Directorate and the Office of the National Cyber Director (ONCD), created in 2021, coordinate national cybersecurity strategy and policy.
Which U.S. federal agency has the primary civilian cybersecurity mission for protecting critical infrastructure under the Cybersecurity and Infrastructure Security Agency Act of 2018?