DRI Regulations, Standards, and Compliance 2 — Questions and Answers
Question 1: Which NIST publication provides the primary framework for federal agency information security programs, including contingency planning requirements?
- NIST SP 800-34
- NIST SP 800-53 (Correct answer)
- NIST SP 800-137
- NIST SP 800-61
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls for federal information systems, including contingency planning (CP) control family requirements.
Question 2: Under HIPAA's Security Rule, covered entities are required to implement a contingency plan that includes all of the following EXCEPT:
- Data backup plan
- Disaster recovery plan
- Business continuity plan (Correct answer)
- Emergency access procedure
Correct answer: Business continuity plan
HIPAA's Security Rule requires a data backup plan, disaster recovery plan, emergency mode operation plan, testing and revision procedures, and applications and data criticality analysis — a standalone 'business continuity plan' is not listed as a required addressable or required implementation specification.
Question 3: The Sarbanes-Oxley Act (SOX) Section 404 primarily impacts BC/DR programs because it requires:
- Annual disaster recovery testing of all critical systems
- Management assessment and auditor attestation of internal controls over financial reporting (Correct answer)
- Real-time backup of all financial data to a geographically separate site
- Board-level approval of all business continuity plans
Correct answer: Management assessment and auditor attestation of internal controls over financial reporting
SOX Section 404 requires management to assess and external auditors to attest to the effectiveness of internal controls over financial reporting, which directly implicates IT availability and recovery capabilities.
Question 4: ISO 22301:2019 replaced which predecessor standard for business continuity management systems?
- BS 25999-2 (Correct answer)
- ISO 27001:2013
- NFPA 1600:2016
- ISO 22313:2012
Correct answer: BS 25999-2
BS 25999-2 was the British Standard for BCMS that ISO 22301 replaced and internationalized when first published in 2012 and subsequently updated in 2019.
Question 5: Which regulatory body oversees business continuity and operational resilience requirements for U.S. federally insured depository institutions?
- SEC
- FINRA
- FDIC (Correct answer)
- CFTC
Correct answer: FDIC
The FDIC, along with the OCC and Federal Reserve, issues guidance on business continuity planning for federally insured depository institutions through the FFIEC IT Examination Handbook.
Question 6: The FFIEC Business Continuity Management booklet recommends that financial institutions define recovery time objectives based primarily on:
- Regulatory mandates from the FDIC
- Results of the business impact analysis (Correct answer)
- Industry benchmarks from peer institutions
- Vendor-provided recovery capabilities
Correct answer: Results of the business impact analysis
FFIEC guidance directs institutions to derive RTOs from the business impact analysis, which identifies time-sensitivity of processes and the maximum tolerable downtime for critical functions.
Question 7: Under GDPR, if a data breach affects personal data availability (e.g., ransomware destroying backups), the controller must notify the supervisory authority within:
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it.
Which NIST publication provides the primary framework for federal agency information security programs, including contingency planning requirements?