CSS Industry Standards & Compliance 3 — Questions and Answers
Question 1: A healthcare customer asks about compliance requirements for their video surveillance system. Which federal regulation is most relevant?
- SOX (Sarbanes-Oxley)
- HIPAA (Health Insurance Portability and Accountability Act) (Correct answer)
- PCI DSS
- FCRA
Correct answer: HIPAA (Health Insurance Portability and Accountability Act)
HIPAA's Privacy and Security Rules affect how video surveillance footage containing patient information must be stored, accessed, and protected.
Question 2: What is the primary purpose of a UL Listing for an alarm panel?
- To guarantee the device cannot be defeated
- To certify the product meets specific safety and performance standards (Correct answer)
- To replace the need for a state contractor license
- To qualify the homeowner for a tax credit
Correct answer: To certify the product meets specific safety and performance standards
A UL Listing indicates that product samples have been tested and evaluated against established safety and performance standards by Underwriters Laboratories.
Question 3: Which FCC rule part most directly governs the radio frequency transmitters used in wireless security alarm systems?
- FCC Part 15 (Correct answer)
- FCC Part 68
- FCC Part 90
- FCC Part 47
Correct answer: FCC Part 15
FCC Part 15 regulates unlicensed intentional radiators, which includes the low-power RF transmitters commonly used in wireless alarm sensors.
Question 4: An alarm company wants its monitoring center to achieve UL 2050 listing. Which of the following is a key requirement?
- The center must be located within 100 miles of all accounts
- The center must pass periodic UL inspections and audits (Correct answer)
- All operators must hold a state security license
- The center must use only UL-listed alarm panels
Correct answer: The center must pass periodic UL inspections and audits
UL 2050 listing requires central stations to undergo and pass unannounced UL inspections to verify ongoing compliance with operational and physical security standards.
Question 5: A retail customer processes credit cards. Which compliance framework should the security salesperson consider when designing the surveillance and access control system?
- ISO 27001
- PCI DSS (Payment Card Industry Data Security Standard) (Correct answer)
- NERC CIP
- FISMA
Correct answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS includes physical security requirements such as access control to cardholder data environments and video surveillance of sensitive areas.
Question 6: ESA's NTS (National Training School) provides training programs primarily aimed at which audience?
- Law enforcement dispatchers
- Electronic security industry professionals (Correct answer)
- Insurance underwriters
- Building code inspectors
Correct answer: Electronic security industry professionals
ESA's National Training School offers technical and business training programs designed for electronic security industry professionals including technicians and salespeople.
Question 7: When a new commercial alarm system is installed, most jurisdictions require the customer to obtain what before police response will be dispatched?
- A UL certificate
- A false alarm insurance rider
- An alarm permit (Correct answer)
- A letter of intent from the alarm company
Correct answer: An alarm permit
Most municipalities require alarm system users to register their system and obtain a local alarm permit before police will respond to alarm signals.
A healthcare customer asks about compliance requirements for their video surveillance system.
Which federal regulation is most relevant?