← All GRC Flashcard Decks

Compliance Standards & Regulatory Requirements Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Standards & Regulatory Requirements flashcards as text
  1. An organization storing sensitive data in AWS wants to achieve FedRAMP authorization. Which step must come FIRST in the formal authorization process?

    Answer: Complete a System Security Plan (SSP)

    The FedRAMP authorization process begins with completing a System Security Plan (SSP) that documents all security controls implemented in the cloud system.

  2. Under NERC CIP standards, which standard addresses Physical Security of BES Cyber Systems?

    Answer: NERC CIP-006

    NERC CIP-006 establishes requirements for physical security plans to protect BES (Bulk Electric System) Cyber Systems from unauthorized physical access.

  3. Which element is NOT one of the three pillars of the EU-US Data Privacy Framework that replaced Privacy Shield?

    Answer: Binding corporate rules for transfers

    The EU-US Data Privacy Framework's three pillars address data protection obligations, redress mechanisms, and US government surveillance safeguards — not binding corporate rules.

  4. SOC 2 Type II reports differ from Type I reports primarily because Type II reports cover:

    Answer: The design AND operating effectiveness of controls over a period of time

    SOC 2 Type II reports evaluate both the design suitability and the operating effectiveness of controls over a minimum review period (typically 6–12 months).

  5. Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age?

    Answer: 13

    COPPA requires verifiable parental consent before collecting, using, or disclosing personal information from children under 13 years of age.

  6. Which ISO standard specifically addresses privacy information management systems (PIMS) and is designed to complement ISO/IEC 27001?

    Answer: ISO/IEC 27701

    ISO/IEC 27701 extends ISO/IEC 27001 and 27002 to include privacy requirements, providing a framework for establishing, implementing, and maintaining a PIMS.

  7. A healthcare organization suffers a breach affecting 600 patients in one state. Under HIPAA's Breach Notification Rule, what is the notification deadline to HHS?

    Answer: Within 60 days of the end of the calendar year

    For breaches affecting fewer than 500 individuals, covered entities must notify HHS within 60 days after the end of the calendar year in which the breach was discovered.