← All GRC Flashcard Decks

Regulatory and Legal Compliance Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory and Legal Compliance flashcards as text
  1. Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?

    Answer: Section 404

    SOX Section 404 requires management to assess internal controls over financial reporting and external auditors to attest to that assessment.

  2. A company operating in California collects personal data from residents. Under the California Consumer Privacy Act (CCPA), what right allows consumers to prevent the sale of their personal information?

    Answer: Right to opt-out

    The CCPA grants consumers the right to opt-out of the sale of their personal information to third parties.

  3. Which U.S. federal law establishes privacy protections for individually identifiable health information held by covered entities and business associates?

    Answer: HIPAA

    HIPAA (Health Insurance Portability and Accountability Act) establishes national standards to protect individually identifiable health information.

  4. An organization subject to PCI DSS discovers a third-party vendor processed cardholder data without a signed agreement. Which PCI DSS requirement has been violated?

    Answer: Requirement 12 – Maintain an information security policy

    PCI DSS Requirement 12 mandates maintaining agreements with service providers that include acknowledgment of their responsibility for cardholder data security.

  5. The EU General Data Protection Regulation (GDPR) requires organizations to appoint a Data Protection Officer (DPO) in which scenario?

    Answer: When the core activities involve large-scale processing of special category data

    GDPR mandates a DPO when core activities consist of large-scale processing of special category data or large-scale systematic monitoring of data subjects.

  6. Which regulatory framework governs export controls on dual-use items, software, and technology from the United States?

    Answer: Export Administration Regulations (EAR)

    The Export Administration Regulations (EAR) govern the export and re-export of most commercial and dual-use items, software, and technology.

  7. A financial institution must implement a Customer Identification Program (CIP) as part of its Bank Secrecy Act obligations. What is the primary purpose of the CIP?

    Answer: To verify the identity of customers opening accounts

    The CIP requires financial institutions to verify the identity of individuals opening accounts to prevent money laundering and terrorist financing.