โ† All CySA+ Test Flashcard Decks

Compliance Frameworks Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Frameworks flashcards as text
  1. Which NIST CSF v2.0 function was newly added compared to the original five functions?

    Answer: Govern

    NIST CSF v2.0 added the Govern function to address cybersecurity risk governance, strategy, and supply chain risk management at the organizational level.

  2. A security analyst is reviewing a third-party vendor's SOC 2 Type II report. The report covers availability and confidentiality criteria. What are these criteria formally called?

    Answer: Trust Service Criteria (TSC)

    AICPA defines the five Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) used in SOC 2 engagements.

  3. Under GDPR, which legal basis allows processing of personal data when the data subject has given clear consent for a specific purpose?

    Answer: Consent

    Consent under GDPR Article 6(1)(a) must be freely given, specific, informed, and unambiguous for each processing purpose.

  4. Which NIST SP 800-61 phase occurs immediately after detecting and analyzing a potential incident?

    Answer: Containment, Eradication, and Recovery

    NIST SP 800-61 defines four phases; Containment, Eradication, and Recovery follow the Detection and Analysis phase.

  5. A financial institution must comply with the Gramm-Leach-Bliley Act (GLBA). Which safeguard rule element requires designation of a qualified individual to oversee the information security program?

    Answer: Qualified Individual designation

    The FTC Safeguards Rule under GLBA requires financial institutions to designate a qualified individual responsible for overseeing and implementing the information security program.

  6. In the context of CIS Controls v8, what distinguishes Implementation Group 1 (IG1) from IG2 and IG3?

    Answer: IG1 represents essential cyber hygiene for all organizations, especially smaller ones

    IG1 is the minimum standard of cyber hygiene applicable to all organizations, particularly those with limited resources and cybersecurity expertise.

  7. Which regulation requires organizations to perform a Data Protection Impact Assessment (DPIA) before processing that is 'likely to result in a high risk'?

    Answer: GDPR

    GDPR Article 35 mandates a DPIA for processing activities likely to result in high risk to individuals' rights and freedoms, particularly with new technologies.

Compliance Frameworks Flashcards โ€” CySA+ Test Study Cards with Answers