← All CSM Flashcard Decks

Regulatory Compliance & Governance Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Governance flashcards as text
  1. What is the primary purpose of a SOC 2 Type II audit report in a software vendor context?

    Answer: To provide assurance that security controls were operating effectively over a defined period

    A SOC 2 Type II report provides an independent auditor's opinion that a service organization's security controls were suitably designed and operated effectively over a review period (typically 6–12 months).

  2. Which GDPR principle requires that personal data be kept in a form that permits identification of individuals for no longer than necessary?

    Answer: Storage limitation

    The storage limitation principle (GDPR Article 5(1)(e)) requires personal data to be kept only as long as necessary for its specified purpose.

  3. A software manager is implementing controls for a PCI DSS-compliant application. Which network segmentation approach best reduces the scope of PCI DSS compliance?

    Answer: Using VLANs to isolate the cardholder data environment (CDE)

    Network segmentation using VLANs or firewalls to isolate the CDE reduces PCI DSS scope by limiting which systems interact with cardholder data.

  4. Under the NIST Cybersecurity Framework (CSF), which core function focuses on detecting the occurrence of a cybersecurity event?

    Answer: Detect

    The Detect function of the NIST CSF focuses on developing and implementing activities to identify the occurrence of a cybersecurity event in a timely manner.

  5. An organization must demonstrate compliance with export control regulations when distributing encryption software internationally. Which U.S. regulation primarily governs this?

    Answer: EAR (Export Administration Regulations)

    The EAR, administered by the Bureau of Industry and Security (BIS), governs the export of dual-use items including encryption software and technology.

  6. In software governance, a 'policy exception' process is used when:

    Answer: A business need requires deviation from an established policy temporarily

    A policy exception process provides a formal, documented mechanism for granting temporary deviations from policy when business necessity requires it, with defined compensating controls.

  7. Which Children's Online Privacy Protection Act (COPPA) requirement applies to software products that are 'directed to children under 13'?

    Answer: Verifiable parental consent before collecting personal information

    COPPA requires operators of websites or online services directed to children under 13 to obtain verifiable parental consent before collecting, using, or disclosing children's personal information.