Regulatory and Legal Compliance Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory and Legal Compliance flashcards as text
Under the Americans with Disabilities Act (ADA), which title specifically prohibits discrimination by private employers with 15 or more employees?
Answer: Title I
ADA Title I prohibits private employers with 15 or more employees from discriminating against qualified individuals with disabilities in employment.
A healthcare organization receives a subpoena for patient records. Under HIPAA, what should be the organization's first step before disclosing the records?
Answer: Notify the patient and provide an opportunity to object
HIPAA requires covered entities to notify the patient and give them a chance to object before disclosing PHI in response to a subpoena not accompanied by a court order.
The concept of 'privacy by design' in regulatory compliance requires that privacy protections be integrated at which stage of system development?
Answer: From the earliest design phase onward
Privacy by design mandates that privacy protections be embedded into systems and processes from the beginning of development, not added as an afterthought.
Which regulatory body oversees compliance with the Fair Credit Reporting Act (FCRA) for most entities?
Answer: Consumer Financial Protection Bureau (CFPB)
The Consumer Financial Protection Bureau (CFPB) has primary enforcement authority over the FCRA for most entities that use or furnish consumer reports.
An organization implements a compliance training program but employees later repeat the same violations. According to the DOJ's guidance on effective compliance programs, what is the most likely deficiency?
Answer: Training that is not reinforced through consistent enforcement and discipline
The DOJ emphasizes that training must be supported by consistent disciplinary action; without enforcement, employees learn that policies are not seriously enforced.
Under the EU's NIS2 Directive, which sector is newly included compared to the original NIS Directive?
Answer: Public administration
NIS2 expanded coverage to include public administration, among other new sectors, broadening the scope of cybersecurity obligations across the EU.
A company subject to SEC regulations discovers a material cybersecurity incident. Under the SEC's 2023 cybersecurity disclosure rules, within how many business days must it file a Form 8-K disclosure?
Answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.