Compliance Standards & Regulatory Requirements Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Standards & Regulatory Requirements flashcards as text
Which compliance framework is specifically designed to secure controlled unclassified information (CUI) in non-federal systems and organizations?
Answer: NIST SP 800-171
NIST SP 800-171 provides security requirements for protecting CUI in nonfederal information systems, often required by defense contractors.
Under HIPAA, a Business Associate Agreement (BAA) is required when a third party does which of the following?
Answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is required whenever a third-party business associate creates, receives, maintains, or transmits PHI while performing services for a covered entity.
Which PCI DSS requirement mandates that cardholder data environments must restrict inbound and outbound traffic to only that which is necessary?
Answer: Requirement 1 — Install and maintain network security controls
PCI DSS Requirement 1 focuses on network security controls, including firewalls and router configurations that restrict unnecessary traffic to and from the cardholder data environment.
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to designate a qualified individual responsible for overseeing what?
Answer: Customer information security program
The GLBA Safeguards Rule requires financial institutions to designate a qualified individual to oversee, implement, and enforce the information security program.
Under GDPR, which legal basis allows an organization to process personal data without consent when it is necessary to fulfill a contract with the data subject?
Answer: Contractual necessity
Article 6(1)(b) of GDPR permits processing personal data without consent when it is necessary for the performance of a contract to which the data subject is a party.
COBIT 2019 is primarily used to govern and manage which domain?
Answer: Enterprise information and technology
COBIT 2019 is an internationally recognized framework for the governance and management of enterprise information and technology (EGIT).
Which regulation enacted after the 2001 financial scandals requires CEOs and CFOs to personally certify the accuracy of financial reports?
Answer: Sarbanes-Oxley Act Section 302
SOX Section 302 requires principal executive and financial officers to personally certify the accuracy and completeness of periodic SEC financial reports.