โ† All CSM Flashcard Decks

Regulatory Compliance & Governance Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Governance flashcards as text
  1. When conducting a Business Impact Analysis (BIA) for regulatory compliance purposes, what is the primary output used in subsequent risk management activities?

    Answer: The Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for critical systems

    A BIA produces RTO and RPO values that define how quickly systems must be restored and how much data loss is acceptable, driving continuity and recovery planning.

  2. A software manager receives a legal hold notice related to pending litigation. Which immediate action is required regarding relevant data?

    Answer: Suspend normal data retention schedules and preserve all potentially relevant data

    A legal hold (litigation hold) requires suspending routine data deletion and preserving all potentially relevant electronically stored information (ESI) to meet discovery obligations.

  3. Under which circumstance does HIPAA's Breach Notification Rule require notifying the U.S. Department of Health and Human Services (HHS) within 60 days of discovery?

    Answer: A breach of unsecured PHI affecting 500 or more individuals

    HIPAA's Breach Notification Rule requires covered entities to notify HHS within 60 days when a breach of unsecured PHI affects 500 or more individuals.

  4. In IT governance, what distinguishes a 'control objective' from a 'control activity'?

    Answer: A control objective states what should be achieved; a control activity is the specific action taken to achieve it

    A control objective defines the desired outcome (e.g., 'prevent unauthorized access'), while a control activity is the specific mechanism implemented to achieve that outcome (e.g., 'enforce MFA').

  5. Which software licensing compliance issue creates the greatest financial and legal risk for an organization?

    Answer: Deploying more software instances than permitted by the purchased license (underlicensing)

    Underlicensing (using more licenses than purchased) exposes organizations to audits, back-payment demands, legal action, and substantial financial penalties from software vendors.

  6. A software manager is establishing a Vendor Risk Management (VRM) program. Which control is considered the minimum baseline for fourth-party risk (vendors of vendors)?

    Answer: Requiring primary vendors to contractually flow down security requirements to their subcontractors

    Requiring primary vendors to flow down security and compliance obligations to their subcontractors is the foundational fourth-party risk control, as direct auditing of all subcontractors is impractical.

  7. Which governance artifact formally defines the roles, responsibilities, and decision-making authority for IT and software management within an organization?

    Answer: RACI matrix

    A RACI matrix (Responsible, Accountable, Consulted, Informed) formally documents who is responsible and accountable for each governance activity and decision.