Regulatory Compliance & Governance Flashcards
7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Governance flashcards as text
Which ISO standard provides a framework specifically for information security management systems (ISMS)?
Answer: ISO 27001
ISO/IEC 27001 is the international standard for establishing, implementing, maintaining, and continually improving an ISMS.
Under the California Consumer Privacy Act (CCPA), which right allows consumers to request that a business stop selling their personal information?
Answer: Right to Opt-Out
The Right to Opt-Out under CCPA (Section 1798.120) allows consumers to direct businesses to stop selling their personal information.
A software manager must ensure audit trails are tamper-evident. Which technical control best supports this governance requirement?
Answer: Cryptographic hashing and write-once log storage
Cryptographic hashing combined with write-once (WORM) storage makes audit logs tamper-evident by detecting any unauthorized modification.
In a software governance context, what does 'separation of duties' primarily prevent?
Answer: Single individuals from having unchecked control over critical processes
Separation of duties (SoD) ensures no single person can control all aspects of a critical process, reducing fraud and error risk.
Which regulatory framework is mandatory for U.S. federal information systems and establishes minimum security requirements based on system impact levels?
Answer: FISMA/NIST SP 800-53
FISMA (Federal Information Security Modernization Act) mandates compliance with NIST SP 800-53 security controls for all U.S. federal information systems.
During a software procurement review, a manager finds a vendor's product collects telemetry data and sends it to servers in a non-EU country. Under GDPR, which mechanism can lawfully authorize this transfer?
Answer: Standard Contractual Clauses (SCCs) approved by the European Commission
Standard Contractual Clauses (SCCs) are an approved GDPR transfer mechanism for moving personal data to third countries without an adequacy decision.
A compliance audit finds that software developers have direct write access to the production database. Which governance principle is most clearly violated?
Answer: Least privilege
The principle of least privilege requires users to have only the minimum access necessary for their role; developers typically should not have write access to production.