CSL CSL Legal, Regulatory & Ethical Frameworks 2 — Questions and Answers
Question 1: What does the NIST Cybersecurity Framework's 'Govern' function (added in CSF 2.0) primarily address?
- Technical network monitoring capabilities
- Organizational context, risk management strategy, and cybersecurity oversight (Correct answer)
- Incident recovery and business continuity procedures
- Threat intelligence sharing with external partners
Correct answer: Organizational context, risk management strategy, and cybersecurity oversight
The new Govern function in NIST CSF 2.0 focuses on establishing context, risk management strategy, roles and responsibilities, and oversight of cybersecurity programs.
Question 2: Under PCI DSS, what is a Qualified Security Assessor (QSA) responsible for?
- Developing cardholder data encryption algorithms
- Conducting formal PCI DSS compliance assessments for merchants and service providers (Correct answer)
- Issuing PCI DSS certifications to payment card networks
- Designing payment processing infrastructure
Correct answer: Conducting formal PCI DSS compliance assessments for merchants and service providers
QSAs are certified by the PCI Security Standards Council to conduct formal PCI DSS assessments and issue Reports on Compliance (ROC) for Level 1 merchants and service providers.
Question 3: What is the primary purpose of a Bug Bounty program from a legal and ethical perspective?
- To compete with other organizations for security talent
- To create a legal, authorized channel for external researchers to report vulnerabilities (Correct answer)
- To eliminate the need for internal security testing
- To publicly disclose all discovered vulnerabilities immediately
Correct answer: To create a legal, authorized channel for external researchers to report vulnerabilities
Bug bounty programs establish clear legal authorization and safe harbor provisions that allow external researchers to test defined systems and report findings without fear of prosecution.
Question 4: Which ethical obligation does a cybersecurity professional have when discovering evidence of a crime during an authorized security assessment?
- Delete the evidence to protect the client's reputation
- Immediately stop the assessment and report findings to designated legal counsel or law enforcement (Correct answer)
- Share the evidence publicly to warn the industry
- Continue the assessment and include findings in the final report only
Correct answer: Immediately stop the assessment and report findings to designated legal counsel or law enforcement
Discovering evidence of a crime requires stopping the assessment to preserve evidence integrity and notifying appropriate legal authorities through proper channels.
Question 5: What is the significance of a 'safe harbor' provision in a vulnerability disclosure policy?
- It protects the organization from all cybersecurity liability
- It grants legal protection to researchers who follow the policy's guidelines when reporting vulnerabilities (Correct answer)
- It limits the types of vulnerabilities researchers may report
- It allows organizations to delay patching without penalty
Correct answer: It grants legal protection to researchers who follow the policy's guidelines when reporting vulnerabilities
Safe harbor provisions assure security researchers that they will not face legal action if they discover and responsibly disclose vulnerabilities while following the policy's defined rules.
Question 6: Under FISMA, which organization is responsible for setting minimum security standards for US federal information systems?
- Department of Homeland Security (DHS)
- National Institute of Standards and Technology (NIST) (Correct answer)
- Office of Management and Budget (OMB)
- Cybersecurity and Infrastructure Security Agency (CISA)
Correct answer: National Institute of Standards and Technology (NIST)
FISMA assigns NIST the responsibility for developing and publishing the security standards and guidelines that federal agencies must follow to protect their information systems.
What does the NIST Cybersecurity Framework's 'Govern' function (added in CSF 2.0) primarily address?