CSS CSS Compliance & Regulatory Frameworks 2 — Questions and Answers
Question 1: What is the difference between a security audit and a security assessment?
- An audit measures compliance against a defined standard; an assessment evaluates overall security posture and risk (Correct answer)
- An assessment is more formal and legally binding than an audit
- They are identical processes with different names
- An audit focuses on vulnerabilities; an assessment checks policies only
Correct answer: An audit measures compliance against a defined standard; an assessment evaluates overall security posture and risk
Audits verify adherence to specific requirements or standards, while assessments take a broader view of security effectiveness and risk exposure.
Question 2: Which US law imposes security and privacy requirements on financial institutions to protect customer financial information?
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- HIPAA
- SOX
- FERPA
Correct answer: Gramm-Leach-Bliley Act (GLBA)
GLBA's Safeguards Rule requires financial institutions to implement a comprehensive information security program to protect customer financial data.
Question 3: What is the primary goal of a data protection impact assessment (DPIA)?
- Identifies and mitigates privacy risks before implementing new processing activities involving personal data (Correct answer)
- Certifies that all data is encrypted in transit
- Audits employee access to sensitive files
- Measures network bandwidth consumption
Correct answer: Identifies and mitigates privacy risks before implementing new processing activities involving personal data
A DPIA is required by GDPR for high-risk processing activities and systematically analyzes how personal data is used and what risks need to be mitigated.
Question 4: What does the GDPR 72-hour breach notification requirement mandate?
- Organizations must notify the supervisory authority within 72 hours of becoming aware of a personal data breach (Correct answer)
- Organizations have 72 days to notify affected individuals
- Security breaches must be resolved within 72 hours
- Only breaches affecting more than 72,000 individuals require notification
Correct answer: Organizations must notify the supervisory authority within 72 hours of becoming aware of a personal data breach
GDPR Article 33 requires organizations to notify the relevant data protection authority within 72 hours of discovering a breach that poses a risk to individuals.
Question 5: Which compliance framework specifically addresses security controls for US federal government cloud deployments?
- FedRAMP (Federal Risk and Authorization Management Program) (Correct answer)
- PCI DSS
- ISO 27001
- HITRUST
Correct answer: FedRAMP (Federal Risk and Authorization Management Program)
FedRAMP provides a standardized security assessment and authorization framework for cloud products and services used by US federal agencies.
Question 6: What is a 'right to erasure' (right to be forgotten) under GDPR?
- An individual's right to request deletion of their personal data when it is no longer necessary for its original purpose (Correct answer)
- The organization's right to delete old data without notice
- A requirement to purge all data after 5 years
- An automatic deletion system mandated for all cloud storage
Correct answer: An individual's right to request deletion of their personal data when it is no longer necessary for its original purpose
GDPR Article 17 grants individuals the right to request that their personal data be deleted under certain circumstances, such as when consent is withdrawn.
What is the difference between a security audit and a security assessment?