Regulatory Frameworks & Compliance Flashcards
7 cards from real Excel VBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
Under GLBA (Gramm-Leach-Bliley Act), a VBA workbook stores customer financial information. Which control is most appropriate?
Answer: Encrypting the workbook with a strong password and restricting access via VBA-enforced user authentication
GLBA requires financial institutions to protect customer financial information through administrative, technical, and physical safeguards, including encryption and access controls.
A VBA macro processes export-controlled technical data under ITAR. What access control should be implemented?
Answer: Check the current Windows username at workbook open and terminate if the user is not on an approved US-person list
ITAR restricts controlled technical data to US persons only; VBA can enforce this by checking user identity against an approved list at runtime.
Which VBA approach supports ISO 27001 Annex A control A.12.4.1 (Event Logging) for a spreadsheet used in an ISMS?
Answer: Writing a timestamped entry to a secure log worksheet for every Workbook_Open, Save, and Close event
ISO 27001 A.12.4.1 requires event logging of user activities and security events; VBA event handlers that log every open, save, and close action fulfill this control.
A VBA solution handles data subject to CCPA. A California resident submits an opt-out request. What must the macro do?
Answer: Immediately cease selling or sharing the resident's personal information and update their record with an opt-out timestamp
CCPA gives California residents the right to opt out of the sale of their personal information, requiring immediate action to stop data sharing and record the opt-out.
When a VBA macro must comply with NIST SP 800-53 control AU-9 (Protection of Audit Information), which technique is appropriate?
Answer: Writing audit records to a hidden worksheet protected with an admin-only password and verifying log integrity with a hash
NIST AU-9 requires protecting audit information from unauthorized access, modification, and deletion; password-protected logs with integrity checks fulfill this control.
A healthcare VBA application must comply with the HITECH Act's breach notification rule. Which capability should be built in?
Answer: Detection logic that identifies when PHI has been accessed without authorization and automatically notifies the Privacy Officer
HITECH strengthened HIPAA breach notification requirements, so VBA applications handling PHI should detect unauthorized access and trigger timely notification workflows.
An SOX-compliant VBA macro must prevent back-dating of journal entries. Which implementation achieves this?
Answer: Comparing the user-entered date to Now() and rejecting entries dated more than the allowable posting period in the past
SOX controls require preventing fraudulent back-dating of financial entries; validating that posted dates fall within the allowable period enforces this control.