CSL CSL Legal, Regulatory & Ethical Considerations 2 — Questions and Answers
Question 1: What is GDPR's relevance to US-based organizations?
- Organizations processing personal data of EU residents must comply with GDPR regardless of where the organization is based (Correct answer)
- GDPR only applies to European companies
- GDPR applies only to healthcare data
- US companies are exempt from GDPR if they have no EU offices
Correct answer: Organizations processing personal data of EU residents must comply with GDPR regardless of where the organization is based
GDPR applies based on where data subjects (individuals) are located, not where the organization is based — US companies with EU customers or website visitors must comply.
Question 2: What is the legal concept of 'negligence' in the context of cybersecurity liability?
- Failure to implement reasonable security measures that a prudent organization in the same industry would have adopted (Correct answer)
- Intentionally attacking another organization's systems
- Failing to file tax returns on time
- Ignoring vendor contracts
Correct answer: Failure to implement reasonable security measures that a prudent organization in the same industry would have adopted
Cybersecurity negligence claims arise when organizations fail to implement security controls considered reasonable and standard for their industry, and a breach results from that failure.
Question 3: Which US federal law requires financial institutions to implement a written information security program?
- The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Correct answer)
- The Sarbanes-Oxley Act
- The Children's Online Privacy Protection Act (COPPA)
- The Electronic Communications Privacy Act
Correct answer: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program protecting customer financial data.
Question 4: What is the purpose of an 'acceptable use policy (AUP)' from a legal and ethical standpoint?
- Define permitted and prohibited uses of organizational systems, establishing a legal basis for enforcement actions (Correct answer)
- Grant employees unlimited system access
- Replace security awareness training
- Satisfy software licensing requirements
Correct answer: Define permitted and prohibited uses of organizational systems, establishing a legal basis for enforcement actions
An AUP establishes clear, documented rules for system use, creating the legal and ethical basis for monitoring, enforcement, and disciplinary action when violations occur.
Question 5: A CSL leader is asked to authorize an offensive security test against a partner organization's system. What is the primary legal concern?
- Without explicit written authorization from the target organization, the test may violate the CFAA regardless of business relationships (Correct answer)
- Business partnerships automatically authorize security testing
- Only government systems require written authorization for penetration tests
- Offensive tests are always legal if they improve security
Correct answer: Without explicit written authorization from the target organization, the test may violate the CFAA regardless of business relationships
The CFAA prohibits unauthorized computer access — even well-intentioned security testing requires explicit written authorization from the system owner to be legally protected.
Question 6: What does 'privacy by design' require from a CSL perspective?
- Embed privacy protections into systems and processes from the outset rather than adding them retroactively (Correct answer)
- Post privacy policies only on public websites
- Only apply privacy protections to customer-facing systems
- Delay privacy reviews until after system deployment
Correct answer: Embed privacy protections into systems and processes from the outset rather than adding them retroactively
Privacy by design mandates that privacy protections are built into systems from the design phase, reducing privacy risk exposure and demonstrating regulatory compliance proactivity.
What is GDPR's relevance to US-based organizations?