Cyber Security Jobs Security Compliance and Regulations 1 — Questions and Answers
Question 1: Which US regulation requires healthcare organizations to protect patient health information (PHI)?
- HIPAA (Correct answer)
- PCI DSS
- GDPR
- SOX
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) mandates security and privacy protections for Protected Health Information in the US healthcare sector.
Question 2: What does PCI DSS govern?
- Security standards for organizations that process credit card payments (Correct answer)
- Environmental regulations for data centers
- US export controls for encryption software
- Rules for government contractor cybersecurity
Correct answer: Security standards for organizations that process credit card payments
PCI DSS (Payment Card Industry Data Security Standard) sets security requirements for any organization that stores, processes, or transmits cardholder data.
Question 3: Which US federal law requires publicly traded companies to maintain accurate financial records and internal controls, including IT controls?
- SOX (Sarbanes-Oxley Act) (Correct answer)
- HIPAA
- FISMA
- COPPA
Correct answer: SOX (Sarbanes-Oxley Act)
SOX (Sarbanes-Oxley Act) requires public companies to implement and audit internal controls over financial reporting, including IT system controls.
Question 4: What is a security audit?
- A systematic evaluation of an organization's security posture against a defined standard (Correct answer)
- An automated malware scan
- A penetration test that uses real exploits
- A real-time network traffic analysis
Correct answer: A systematic evaluation of an organization's security posture against a defined standard
A security audit formally assesses an organization's policies, procedures, and controls against a standard (like ISO 27001 or NIST) to identify gaps.
Question 5: What does FISMA require of US federal agencies?
- Develop, document, and implement agency-wide information security programs (Correct answer)
- Report quarterly earnings to shareholders
- Encrypt all outbound email
- Conduct annual penetration tests on all systems
Correct answer: Develop, document, and implement agency-wide information security programs
FISMA (Federal Information Security Management Act) requires US federal agencies to implement comprehensive information security programs and report annually to OMB.
Question 6: Which framework is most commonly used by US organizations to structure their cybersecurity programs?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ITIL Service Management
- ISO 14001 Environmental
- Six Sigma DMAIC
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework, built around Identify, Protect, Detect, Respond, and Recover functions, is the most widely adopted US cybersecurity management framework.
Which US regulation requires healthcare organizations to protect patient health information (PHI)?