← All GRC Flashcard Decks

Compliance Standards & Regulatory Requirements Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Standards & Regulatory Requirements flashcards as text
  1. Which regulation requires covered entities and business associates to implement safeguards for protected health information (PHI)?

    Answer: HIPAA Security Rule

    The HIPAA Security Rule mandates administrative, physical, and technical safeguards to protect electronic PHI for covered entities and their business associates.

  2. Under PCI DSS, what is the maximum number of days allowed to patch critical vulnerabilities in systems that process cardholder data?

    Answer: 30 days

    PCI DSS Requirement 6.3.3 requires critical patches to be installed within one month (30 days) of release to protect cardholder data environments.

  3. Which NIST publication provides a framework for managing cybersecurity risk using five core functions: Identify, Protect, Detect, Respond, and Recover?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into five core functions to help organizations manage and reduce cyber risk.

  4. GDPR Article 83 establishes maximum fines of up to €20 million or what percentage of global annual turnover for the most serious violations?

    Answer: 4%

    GDPR's highest tier of fines can reach €20 million or 4% of the organization's total global annual turnover, whichever is higher.

  5. ISO/IEC 27001:2022 replaced which previous version of the standard?

    Answer: ISO/IEC 27001:2013

    ISO/IEC 27001:2022 replaced the 2013 version, introducing restructured Annex A controls and alignment with ISO Annex SL harmonized structure.

  6. Which SOX section requires management to assess and report on the effectiveness of internal controls over financial reporting?

    Answer: Section 404

    SOX Section 404 requires management to annually assess internal control over financial reporting (ICFR) and have external auditors attest to that assessment.

  7. The California Consumer Privacy Act (CCPA) grants California residents the right to opt out of which specific business activity?

    Answer: Sale of their personal information

    CCPA gives California residents the right to direct a business to stop selling their personal information to third parties.