DRI Regulatory Compliance & Standards 2 — Questions and Answers
Question 1: The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to have which business continuity element?
- A cybersecurity insurance policy
- A contingency plan that includes data backup, disaster recovery, and emergency operations (Correct answer)
- Annual third-party audits of their recovery capabilities
- Board-level approval of all continuity strategies
Correct answer: A contingency plan that includes data backup, disaster recovery, and emergency operations
HIPAA's Security Rule requires covered entities to implement a contingency plan that includes data backup procedures, disaster recovery procedures, emergency mode operation procedures, testing and revision procedures, and applications and data criticality analysis.
HIPAA's Security Rule (45 CFR § 164.308(a)(7)) is one of the most specific regulatory mandates for business continuity in any industry. It requires covered entities—healthcare providers, health plans, healthcare clearinghouses—and their business associates to maintain contingency plans addressing five required components: data backup (creating retrievable exact copies of ePHI), disaster recovery (restoring lost data), emergency mode operations (maintaining security of ePHI during a disaster), testing and revision (exercising and updating plans), and criticality analysis (assessing the relative criticality of specific applications). Non-compliance can result in civil penalties up to $1.9 million per violation category per year and criminal charges for willful neglect.
Question 2: Which international standard specifically addresses information security management and has direct relevance to IT disaster recovery planning?
- ISO 45001
- ISO 27001 (Correct answer)
- ISO 9001
- ISO 14001
Correct answer: ISO 27001
ISO 27001 is the international standard for information security management systems (ISMS). It includes requirements for business continuity planning specifically for information security, making it directly relevant to IT disaster recovery.
ISO 27001 establishes requirements for an Information Security Management System (ISMS) and includes Annex A control A.17 (now restructured in ISO 27001:2022 as control 5.30), which specifically addresses information security continuity. Organizations certified under ISO 27001 must demonstrate that their business continuity planning incorporates information security requirements—ensuring that security controls are maintained even when operating in recovery mode and that ePHI, financial data, and other sensitive information is protected during and after disasters. ISO 27001 and ISO 22301 (business continuity) are complementary standards that many organizations pursue together to demonstrate comprehensive resilience and security governance.
Question 3: The Sarbanes-Oxley Act (SOX) Section 404 is primarily relevant to business continuity because it requires:
- Mandatory cyber incident reporting to the SEC within 72 hours
- Management assessment of internal controls over financial reporting, including controls supporting system availability (Correct answer)
- Annual penetration testing of financial systems
- Segregation of duties for all financial transactions above $10,000
Correct answer: Management assessment of internal controls over financial reporting, including controls supporting system availability
SOX Section 404 requires management to assess and report on internal controls over financial reporting, which includes IT general controls such as system availability, backup, and recovery—core business continuity elements.
SOX Section 404 mandates that public company management assess the effectiveness of internal controls over financial reporting (ICFR) and that external auditors attest to management's assessment. IT general controls—which encompass system availability, change management, access controls, and data backup/recovery—are foundational to financial system integrity. If financial systems are unavailable due to inadequate disaster recovery, or if data is lost or corrupted due to poor backup practices, financial reporting may be materially misstated. Auditors evaluate whether recovery time objectives (RTOs) and recovery point objectives (RPOs) for financial systems are appropriate and whether recovery capabilities have been tested. SOX compliance thus creates a strong regulatory driver for robust IT business continuity programs.
Question 4: Under GDPR, what must an organization do when a personal data breach affecting individuals' rights occurs?
- Notify the supervisory authority within 72 hours of becoming aware of the breach (Correct answer)
- Conduct an internal audit and file a report within 30 days
- Notify affected individuals immediately without notifying regulators
- Obtain legal counsel before taking any action
Correct answer: Notify the supervisory authority within 72 hours of becoming aware of the breach
GDPR Article 33 requires organizations to notify the relevant supervisory authority (data protection regulator) within 72 hours of becoming aware of a personal data breach, where feasible.
GDPR's breach notification requirements have significant implications for business continuity and incident response planning. Article 33 requires controllers to notify the supervisory authority 'without undue delay and, where feasible, not later than 72 hours after having become aware' of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons. Article 34 additionally requires direct notification to affected individuals when the breach is likely to result in a high risk to their rights. Business continuity plans must incorporate GDPR breach notification procedures, including criteria for assessing breach severity, escalation procedures, documentation requirements, and pre-drafted notification templates. Failure to notify can result in fines of up to €10 million or 2% of global annual turnover.
Question 5: The NIST Cybersecurity Framework (CSF) function 'Recover' directly supports business continuity by focusing on:
- Preventing cyberattacks through access controls and encryption
- Detecting anomalous activity through monitoring
- Developing and implementing restoration activities after a cybersecurity incident (Correct answer)
- Identifying organizational cybersecurity risk through asset management
Correct answer: Developing and implementing restoration activities after a cybersecurity incident
The NIST CSF 'Recover' function focuses on developing and implementing appropriate activities to maintain plans for resilience and restore capabilities or services impaired by a cybersecurity incident—directly supporting business continuity objectives.
The NIST Cybersecurity Framework organizes cybersecurity activities into five core functions: Identify, Protect, Detect, Respond, and Recover. The Recover function encompasses three categories: Recovery Planning (implementing and maintaining recovery plans and procedures), Improvements (incorporating lessons learned from recovery activities), and Communications (coordinating restoration activities with internal and external parties). The Recover function directly maps to traditional BC/DR objectives—RTOs, RPOs, recovery strategies, and plan maintenance. Organizations using the NIST CSF as a compliance framework need to demonstrate that their business continuity program addresses recovery planning in a comprehensive and tested manner. The NIST CSF is voluntary for private organizations but is required by various sector-specific regulations.
Question 6: In a business continuity context, what is the primary purpose of a regulatory compliance matrix?
- To track employee compliance training completion rates
- To map specific regulatory requirements to business continuity program elements and identify gaps (Correct answer)
- To document financial penalties associated with non-compliance
- To record all regulatory audits and their findings
Correct answer: To map specific regulatory requirements to business continuity program elements and identify gaps
A regulatory compliance matrix maps specific regulatory and legal requirements to corresponding elements of the business continuity program, helping organizations identify coverage gaps and ensure all obligations are addressed.
Organizations subject to multiple regulations—SOX, HIPAA, GDPR, sector-specific rules, and industry standards—face the challenge of maintaining a comprehensive BC program that satisfies all requirements without duplication or gaps. A regulatory compliance matrix (also called a compliance crosswalk or requirements matrix) systematically lists each applicable regulation or standard, its specific continuity-related requirements, the corresponding BC program elements that address those requirements, the responsible owner, and the evidence of compliance (test results, policies, audit reports). This tool enables BC managers to demonstrate comprehensive compliance, prioritize remediation efforts where gaps exist, and efficiently prepare for regulatory audits. DRI CBCP practice requires understanding and managing regulatory obligations as a core competency.
The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to have which business continuity element?