Compliance Frameworks Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Frameworks flashcards as text
Which NIST CSF function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, and data?
Answer: Identify
The Identify function establishes the foundation for an effective cybersecurity program by building organizational understanding of risk context.
Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
A healthcare organization uses a third-party billing company that accesses PHI. What agreement must be in place under HIPAA?
Answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement with any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
Which PCI DSS requirement mandates that cardholder data environments be separated from other network segments?
Answer: Requirement 1 — Install and maintain network security controls
PCI DSS Requirement 1 covers network security controls including firewall configuration and network segmentation to isolate the cardholder data environment.
SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports evaluate:
Answer: Controls over a period of time, not just a point in time
SOC 2 Type II assesses the operating effectiveness of controls over a defined period (typically 6–12 months), while Type I only evaluates design at a single point in time.
Which NIST SP 800-53 control family addresses audit and accountability requirements?
Answer: AU — Audit and Accountability
The AU control family in NIST SP 800-53 covers audit event logging, audit record review, protection, and retention.
An organization operating critical infrastructure must comply with NERC CIP. Which standard specifically addresses electronic security perimeters?
Answer: NERC CIP-005
NERC CIP-005 requires entities to identify and protect Electronic Security Perimeters and associated access points for critical cyber assets.