โ† All CSM Flashcard Decks

Regulatory Compliance & Governance Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Governance flashcards as text
  1. Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?

    Answer: Section 404

    SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting annually.

  2. A software manager discovers that a third-party vendor has access to customer PII but has not signed a Data Processing Agreement (DPA). Under GDPR, what is the immediate required action?

    Answer: Execute a DPA before any further data processing

    GDPR Article 28 requires a written DPA to be in place before a processor can lawfully handle personal data on behalf of a controller.

  3. In IT governance frameworks, which COBIT 5 domain is primarily responsible for ensuring that IT services are delivered effectively and efficiently?

    Answer: Deliver, Service and Support (DSS)

    The DSS (Deliver, Service and Support) domain in COBIT 5 focuses on the delivery of IT services and support operations.

  4. Which U.S. federal law primarily governs the privacy and security of protected health information (PHI) in software systems used by healthcare providers?

    Answer: HIPAA

    HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting PHI in healthcare-related software and systems.

  5. A software manager is conducting a risk assessment for compliance purposes. Which approach best aligns with the NIST Risk Management Framework (RMF)?

    Answer: Categorize systems, select controls, implement, assess, authorize, and monitor continuously

    The NIST RMF follows a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor.

  6. Under PCI DSS, what is the maximum number of digits that may be displayed when truncating a Primary Account Number (PAN) for display purposes?

    Answer: First 6 and last 4 digits only

    PCI DSS Requirement 3.3 permits displaying no more than the first six and last four digits of the PAN.

  7. An organization's software audit reveals that change management procedures were bypassed for an emergency hotfix. Which governance control is most directly violated?

    Answer: Change control policy

    Bypassing the change management process violates the change control policy, which ensures all modifications are authorized, tested, and documented.

Regulatory Compliance & Governance Flashcards โ€” CSM Study Cards with Answers