CSL CSL Legal, Regulatory & Ethical Considerations 1 — Questions and Answers
Question 1: Under US law, which federal agency has primary oversight responsibility for cybersecurity in the financial sector?
- The SEC (Securities and Exchange Commission) and banking regulators like FFIEC (Correct answer)
- The FTC only
- The Department of Agriculture
- OSHA
Correct answer: The SEC (Securities and Exchange Commission) and banking regulators like FFIEC
Financial sector cybersecurity oversight falls under the SEC for public companies and FFIEC-member banking regulators (OCC, FDIC, Federal Reserve) for depository institutions.
Question 2: What is the purpose of the SEC's cybersecurity disclosure rules for public companies?
- Require timely public disclosure of material cybersecurity incidents and annual reporting on cybersecurity risk management (Correct answer)
- Mandate specific security technologies for all public companies
- Require public companies to hire a CISO
- Apply HIPAA requirements to financial institutions
Correct answer: Require timely public disclosure of material cybersecurity incidents and annual reporting on cybersecurity risk management
The SEC's 2023 cybersecurity rules require public companies to disclose material incidents within four business days and annually report on their cybersecurity risk management programs.
Question 3: What does the Computer Fraud and Abuse Act (CFAA) primarily govern?
- Unauthorized access to computer systems and networks in the United States (Correct answer)
- Copyright protection for software code
- Data privacy rights of consumers
- Export controls on encryption technology
Correct answer: Unauthorized access to computer systems and networks in the United States
The CFAA is the primary US federal law prohibiting unauthorized access to computer systems, forming the legal basis for prosecuting cybercrime and limiting authorized security testing.
Question 4: A CSL leader must ensure compliance with HIPAA. Which cybersecurity control is explicitly required?
- Access controls limiting ePHI access to authorized users only (Correct answer)
- Mandatory two-factor authentication for all devices
- Full disk encryption on all endpoints
- Public disclosure of all security incidents within 24 hours
Correct answer: Access controls limiting ePHI access to authorized users only
HIPAA's Security Rule requires covered entities to implement access controls ensuring that only authorized individuals can access electronic protected health information (ePHI).
Question 5: What is the primary purpose of state-level data breach notification laws in the US?
- Require organizations to notify affected individuals and regulators when their personal data is exposed in a breach (Correct answer)
- Mandate specific encryption standards for data at rest
- Establish federal cybersecurity standards for all industries
- Regulate how organizations may collect personal data
Correct answer: Require organizations to notify affected individuals and regulators when their personal data is exposed in a breach
State breach notification laws give consumers the right to know when their personal information has been compromised so they can take protective action.
Question 6: Which ethical obligation does a cybersecurity leader have when discovering a significant security vulnerability in a competitor's public-facing system?
- Follow responsible disclosure practices by notifying the affected organization through proper channels (Correct answer)
- Exploit the vulnerability for competitive advantage
- Publish the vulnerability publicly immediately without notification
- Ignore the vulnerability as it is not their responsibility
Correct answer: Follow responsible disclosure practices by notifying the affected organization through proper channels
Responsible disclosure — notifying the affected organization privately and allowing time for remediation before any public disclosure — is the ethical standard for handling discovered vulnerabilities.
Under US law, which federal agency has primary oversight responsibility for cybersecurity in the financial sector?