← All CySA+ Test Flashcard Decks

Compliance Frameworks Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Frameworks flashcards as text
  1. Which NIST CSF function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, and data?

    Answer: Identify

    The Identify function establishes the foundation for an effective cybersecurity program by building organizational understanding of risk context.

  2. Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

  3. A healthcare organization uses a third-party billing company that accesses PHI. What agreement must be in place under HIPAA?

    Answer: Business Associate Agreement (BAA)

    HIPAA requires a Business Associate Agreement with any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity.

  4. Which PCI DSS requirement mandates that cardholder data environments be separated from other network segments?

    Answer: Requirement 1 — Install and maintain network security controls

    PCI DSS Requirement 1 covers network security controls including firewall configuration and network segmentation to isolate the cardholder data environment.

  5. SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports evaluate:

    Answer: Controls over a period of time, not just a point in time

    SOC 2 Type II assesses the operating effectiveness of controls over a defined period (typically 6–12 months), while Type I only evaluates design at a single point in time.

  6. Which NIST SP 800-53 control family addresses audit and accountability requirements?

    Answer: AU — Audit and Accountability

    The AU control family in NIST SP 800-53 covers audit event logging, audit record review, protection, and retention.

  7. An organization operating critical infrastructure must comply with NERC CIP. Which standard specifically addresses electronic security perimeters?

    Answer: NERC CIP-005

    NERC CIP-005 requires entities to identify and protect Electronic Security Perimeters and associated access points for critical cyber assets.