← All CSM Flashcard Decks

Regulatory Compliance & Governance Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Governance flashcards as text
  1. Which ISO standard provides a framework specifically for information security management systems (ISMS)?

    Answer: ISO 27001

    ISO/IEC 27001 is the international standard for establishing, implementing, maintaining, and continually improving an ISMS.

  2. Under the California Consumer Privacy Act (CCPA), which right allows consumers to request that a business stop selling their personal information?

    Answer: Right to Opt-Out

    The Right to Opt-Out under CCPA (Section 1798.120) allows consumers to direct businesses to stop selling their personal information.

  3. A software manager must ensure audit trails are tamper-evident. Which technical control best supports this governance requirement?

    Answer: Cryptographic hashing and write-once log storage

    Cryptographic hashing combined with write-once (WORM) storage makes audit logs tamper-evident by detecting any unauthorized modification.

  4. In a software governance context, what does 'separation of duties' primarily prevent?

    Answer: Single individuals from having unchecked control over critical processes

    Separation of duties (SoD) ensures no single person can control all aspects of a critical process, reducing fraud and error risk.

  5. Which regulatory framework is mandatory for U.S. federal information systems and establishes minimum security requirements based on system impact levels?

    Answer: FISMA/NIST SP 800-53

    FISMA (Federal Information Security Modernization Act) mandates compliance with NIST SP 800-53 security controls for all U.S. federal information systems.

  6. During a software procurement review, a manager finds a vendor's product collects telemetry data and sends it to servers in a non-EU country. Under GDPR, which mechanism can lawfully authorize this transfer?

    Answer: Standard Contractual Clauses (SCCs) approved by the European Commission

    Standard Contractual Clauses (SCCs) are an approved GDPR transfer mechanism for moving personal data to third countries without an adequacy decision.

  7. A compliance audit finds that software developers have direct write access to the production database. Which governance principle is most clearly violated?

    Answer: Least privilege

    The principle of least privilege requires users to have only the minimum access necessary for their role; developers typically should not have write access to production.