CSPM Security Industry-Specific Knowledge 3 — Questions and Answers
Question 1: A security project manager is overseeing deployment of an intrusion detection system at a financial institution. Which regulation most directly requires the institution to implement controls that detect unauthorized access to customer financial information?
- PCI DSS
- Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Correct answer)
- HIPAA Security Rule
- SOX Section 404
Correct answer: Gramm-Leach-Bliley Act (GLBA) Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement administrative, technical, and physical safeguards—including access detection—to protect customer financial data.
Question 2: Under the ICD 705 standard, what is the primary purpose of a Sensitive Compartmented Information Facility (SCIF) accreditation?
- To certify that the facility meets physical and technical construction standards for handling classified SCI (Correct answer)
- To authorize personnel to receive SCI briefings
- To validate that TEMPEST countermeasures have been applied to all equipment
- To certify the facility's cybersecurity posture under NIST 800-53
Correct answer: To certify that the facility meets physical and technical construction standards for handling classified SCI
ICD 705 accreditation confirms the SCIF meets the physical, technical, and administrative construction standards required to protect SCI from unauthorized disclosure.
Question 3: Which private security regulatory body in the US issues model licensing legislation that many states use as a template for guard and investigator licensing?
- ASIS International (Correct answer)
- NICB
- BSIS
- NASLEO
Correct answer: ASIS International
ASIS International publishes model private security licensing legislation and advocates for consistent state-level standards across the industry.
Question 4: A hospital's security project team is installing access control on psychiatric units. Which federal law most directly restricts how security footage and incident records involving patients may be used?
- ADA
- HIPAA Privacy Rule (Correct answer)
- 42 CFR Part 2
- EMTALA
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule governs the use and disclosure of protected health information, which includes security records that identify patients.
Question 5: In loss prevention terminology, what does 'shrinkage' specifically measure in a retail security context?
- Physical reduction in store footprint due to renovation
- Inventory loss from theft, error, fraud, and supplier issues (Correct answer)
- Decrease in sales revenue attributable to security incidents
- Reduction in security headcount over a fiscal year
Correct answer: Inventory loss from theft, error, fraud, and supplier issues
Shrinkage is the retail industry term for inventory loss caused by shoplifting, employee theft, administrative errors, and vendor fraud.
Question 6: When designing an executive protection detail, which threat assessment model is most commonly applied to evaluate the credibility and capability of identified threats to a principal?
- CARVER Matrix
- Pathway to Violence model (Correct answer)
- STRIDE Threat Model
- TARA (Threat Agent Risk Assessment)
Correct answer: Pathway to Violence model
The Pathway to Violence model, developed by Calhoun and Weston, identifies behavioral indicators along the progression from grievance to targeted attack, widely used in EP threat assessment.
Question 7: Which US federal statute criminalizes theft of trade secrets and applies directly to corporate espionage investigations managed by a security project team?
- Computer Fraud and Abuse Act (CFAA)
- Economic Espionage Act (EEA) (Correct answer)
- Foreign Corrupt Practices Act (FCPA)
- Defend Trade Secrets Act (DTSA) only
Correct answer: Economic Espionage Act (EEA)
The Economic Espionage Act (18 U.S.C. §§ 1831-1839) criminalizes both foreign-sponsored and domestic theft of trade secrets at the federal level.
A security project manager is overseeing deployment of an intrusion detection system at a financial institution.
Which regulation most directly requires the institution to implement controls that detect unauthorized access to customer financial information?