โ† All GRC Flashcard Decks

Compliance Standards & Regulatory Requirements Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Standards & Regulatory Requirements flashcards as text
  1. Which compliance framework introduced the concept of 'continuous monitoring' as a key component of the Risk Management Framework (RMF)?

    Answer: NIST SP 800-37

    NIST SP 800-37 (RMF) incorporates continuous monitoring as Step 6 of its six-step process to maintain ongoing awareness of security and privacy posture.

  2. Under GDPR, a Data Protection Impact Assessment (DPIA) is MANDATORY when processing is likely to result in:

    Answer: High risk to the rights and freedoms of natural persons

    Article 35 of GDPR requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of individuals, particularly for systematic profiling or sensitive data processing.

  3. Which Dodd-Frank Act provision created the Consumer Financial Protection Bureau (CFPB) to regulate consumer financial products?

    Answer: Title X

    Title X of the Dodd-Frank Wall Street Reform and Consumer Protection Act established the Consumer Financial Protection Bureau (CFPB).

  4. In the context of PCI DSS v4.0, what new approach was introduced alongside the traditional compliance approach?

    Answer: Customized approach

    PCI DSS v4.0 introduced the 'Customized Approach' as an alternative that allows organizations to achieve security objectives using their own controls rather than following prescriptive requirements.

  5. Which regulation governs the privacy of student education records at institutions receiving federal funding?

    Answer: FERPA

    FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at federally funded educational institutions.

  6. When a company processes personal data of EU residents from a third country, GDPR requires an 'adequacy decision' OR which alternative transfer mechanism?

    Answer: Appropriate safeguards such as Standard Contractual Clauses (SCCs)

    In the absence of an adequacy decision, GDPR Article 46 requires appropriate safeguards such as Standard Contractual Clauses (SCCs), binding corporate rules, or approved codes of conduct.

  7. Which CMMC level requires an organization to have a documented and institutionalized cybersecurity program aligned to ALL 110 NIST SP 800-171 practices?

    Answer: CMMC Level 2

    CMMC Level 2 requires implementation of all 110 practices from NIST SP 800-171 and a documented cybersecurity program, with third-party assessments required for critical programs.