CSL Cybersecurity Regulations & Compliance 2 โ Questions and Answers
Question 1: Under the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services?
- Identify
- Protect (Correct answer)
- Detect
- Respond
Correct answer: Protect
The Protect function covers safeguards such as access control, data security, and protective technology to limit the impact of potential cybersecurity events.
Question 2: Which federal law requires civilian federal agencies to inventory their IT assets and implement continuous monitoring programs?
- FISMA (Correct answer)
- HIPAA
- GLBA
- COPPA
Correct answer: FISMA
The Federal Information Security Modernization Act (FISMA) mandates that federal agencies develop, document, and implement an information security program including continuous monitoring.
Question 3: A company subject to PCI DSS stores cardholder data. Which PCI DSS requirement directly addresses the protection of stored cardholder data?
- Requirement 1
- Requirement 3 (Correct answer)
- Requirement 6
- Requirement 10
Correct answer: Requirement 3
PCI DSS Requirement 3 specifically mandates protecting stored cardholder data through encryption, masking, and other techniques.
Question 4: Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect the security and confidentiality of customer information?
- Financial Privacy Rule
- Safeguards Rule (Correct answer)
- Pretexting Protection
- Fair Credit Reporting Act
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a comprehensive information security program to protect customer data.
Question 5: Under GDPR, what is the maximum timeframe for notifying the supervisory authority after discovering a personal data breach?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires controllers to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 6: Which compliance framework is specifically designed for cloud service providers handling U.S. federal government data?
- SOC 2
- FedRAMP (Correct answer)
- ISO 27001
- HITRUST CSF
Correct answer: FedRAMP
FedRAMP (Federal Risk and Authorization Management Program) standardizes security assessment, authorization, and continuous monitoring for cloud products used by federal agencies.
Question 7: A healthcare organization must conduct a Security Risk Analysis under which regulation before using electronic health records?
- HITECH Act
- HIPAA Security Rule (Correct answer)
- CMS Conditions of Participation
- 21st Century Cures Act
Correct answer: HIPAA Security Rule
The HIPAA Security Rule (45 CFR ยง 164.308) explicitly requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI.
Under the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services?