CSS Compliance & Regulatory Frameworks Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CSS Compliance & Regulatory Frameworks flashcards as text
What is the purpose of continuous compliance monitoring in a security program?
Answer: Provides real-time visibility into the compliance posture of systems rather than point-in-time assessments
Continuous compliance monitoring uses automated tools to track controls and configurations in real time, reducing the gap between audits when non-compliance might go undetected.
What does CIS Benchmarks provide to organizations?
Answer: Prescriptive configuration hardening guidelines for operating systems, cloud environments, and applications
CIS Benchmarks are consensus-based secure configuration guidelines developed by security experts for a wide range of platforms and technologies.
Which privacy law in the United States grants California residents rights over their personal data?
Answer: California Consumer Privacy Act (CCPA)
The CCPA gives California residents rights to know what personal data is collected, delete it, and opt out of the sale of their data.
What is the role of a data protection officer (DPO) as required by GDPR?
Answer: Oversees data protection strategy, ensures GDPR compliance, and serves as the contact point for supervisory authorities
GDPR requires certain organizations to appoint a DPO who independently oversees compliance with data protection laws and advises on data processing activities.
What does a gap analysis in compliance management assess?
Answer: The difference between the organization's current security posture and the requirements of a target framework or standard
A gap analysis identifies which required controls are not yet implemented or are insufficiently implemented, enabling the organization to prioritize remediation efforts.
What is the key principle behind privacy by design?
Answer: Privacy protections are embedded into systems and processes from the outset rather than added as an afterthought
Privacy by design integrates data protection principles into the architecture and design of systems from the beginning, rather than bolting them on after development.