CSL Cybersecurity Regulations & Compliance 3 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), which right allows consumers to request that a business delete their personal information?
- Right to Know
- Right to Delete (Correct answer)
- Right to Opt-Out
- Right to Non-Discrimination
Correct answer: Right to Delete
The Right to Delete under CCPA allows consumers to request that businesses delete personal information collected about them, subject to certain exceptions.
Question 2: Which NIST Special Publication provides guidelines for security categorization of federal information and information systems?
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-60 (Correct answer)
- NIST SP 800-137
Correct answer: NIST SP 800-60
NIST SP 800-60 provides guidance for mapping information and information system types to security categories (Low, Moderate, High) as required by FIPS 199.
Question 3: The New York SHIELD Act expanded upon which existing state law to add data security program requirements for businesses handling New Yorkers' private information?
- New York Banking Law
- New York Information Security Breach and Notification Act (Correct answer)
- New York State Technology Law
- New York General Business Law § 349
Correct answer: New York Information Security Breach and Notification Act
The SHIELD Act amended New York's existing breach notification law to also require businesses to implement reasonable data security programs.
Question 4: Under SOC 2, which Trust Service Criteria category covers policies and procedures that management uses to oversee the design, implementation, and operation of controls?
- Availability
- Confidentiality
- Common Criteria (CC) — Control Environment (Correct answer)
- Processing Integrity
Correct answer: Common Criteria (CC) — Control Environment
The Common Criteria section CC1 (Control Environment) in SOC 2 addresses management's oversight structure, including governance, policies, and organizational culture.
Question 5: Which agency enforces the Children's Online Privacy Protection Act (COPPA) in the United States?
- Department of Education
- Federal Communications Commission
- Federal Trade Commission (Correct answer)
- Department of Commerce
Correct answer: Federal Trade Commission
The FTC is the primary enforcement agency for COPPA, which protects the online privacy of children under 13.
Question 6: A company operating in the EU must appoint a Data Protection Officer (DPO) under GDPR when which condition is met?
- The company has more than 50 employees
- The company processes data of more than 1,000 individuals
- Core activities involve large-scale systematic monitoring of individuals (Correct answer)
- The company operates in more than three EU member states
Correct answer: Core activities involve large-scale systematic monitoring of individuals
GDPR Article 37 requires a DPO when an organization's core activities involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data.
Question 7: Which cybersecurity regulation requires operators of critical infrastructure to report significant cyber incidents to CISA within 72 hours under U.S. law?
- Executive Order 14028
- Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) (Correct answer)
- National Defense Authorization Act
- Homeland Security Act
Correct answer: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
CIRCIA, signed into law in 2022, requires covered entities in critical infrastructure sectors to report significant cyber incidents to CISA within 72 hours.
Under the California Consumer Privacy Act (CCPA), which right allows consumers to request that a business delete their personal information?