โ† All CSS Flashcard Decks

CSS Compliance & Regulatory Frameworks Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Compliance & Regulatory Frameworks flashcards as text
  1. What is the difference between a security audit and a security assessment?

    Answer: An audit measures compliance against a defined standard; an assessment evaluates overall security posture and risk

    Audits verify adherence to specific requirements or standards, while assessments take a broader view of security effectiveness and risk exposure.

  2. Which US law imposes security and privacy requirements on financial institutions to protect customer financial information?

    Answer: Gramm-Leach-Bliley Act (GLBA)

    GLBA's Safeguards Rule requires financial institutions to implement a comprehensive information security program to protect customer financial data.

  3. What is the primary goal of a data protection impact assessment (DPIA)?

    Answer: Identifies and mitigates privacy risks before implementing new processing activities involving personal data

    A DPIA is required by GDPR for high-risk processing activities and systematically analyzes how personal data is used and what risks need to be mitigated.

  4. What does the GDPR 72-hour breach notification requirement mandate?

    Answer: Organizations must notify the supervisory authority within 72 hours of becoming aware of a personal data breach

    GDPR Article 33 requires organizations to notify the relevant data protection authority within 72 hours of discovering a breach that poses a risk to individuals.

  5. Which compliance framework specifically addresses security controls for US federal government cloud deployments?

    Answer: FedRAMP (Federal Risk and Authorization Management Program)

    FedRAMP provides a standardized security assessment and authorization framework for cloud products and services used by US federal agencies.

  6. What is a 'right to erasure' (right to be forgotten) under GDPR?

    Answer: An individual's right to request deletion of their personal data when it is no longer necessary for its original purpose

    GDPR Article 17 grants individuals the right to request that their personal data be deleted under certain circumstances, such as when consent is withdrawn.