GRC Compliance Standards & Regulatory Requirements 2 — Questions and Answers
Question 1: Which regulation requires covered entities and business associates to implement safeguards for protected health information (PHI)?
- GLBA
- HIPAA Security Rule (Correct answer)
- SOX Section 404
- FERPA
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates administrative, physical, and technical safeguards to protect electronic PHI for covered entities and their business associates.
Question 2: Under PCI DSS, what is the maximum number of days allowed to patch critical vulnerabilities in systems that process cardholder data?
- 30 days (Correct answer)
- 60 days
- 90 days
- 180 days
Correct answer: 30 days
PCI DSS Requirement 6.3.3 requires critical patches to be installed within one month (30 days) of release to protect cardholder data environments.
Question 3: Which NIST publication provides a framework for managing cybersecurity risk using five core functions: Identify, Protect, Detect, Respond, and Recover?
- NIST SP 800-53
- NIST SP 800-171
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-37
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into five core functions to help organizations manage and reduce cyber risk.
Question 4: GDPR Article 83 establishes maximum fines of up to €20 million or what percentage of global annual turnover for the most serious violations?
- 2%
- 4% (Correct answer)
- 6%
- 10%
Correct answer: 4%
GDPR's highest tier of fines can reach €20 million or 4% of the organization's total global annual turnover, whichever is higher.
Question 5: ISO/IEC 27001:2022 replaced which previous version of the standard?
- ISO/IEC 27001:2005
- ISO/IEC 27001:2013 (Correct answer)
- ISO/IEC 27001:2018
- ISO/IEC 27001:2020
Correct answer: ISO/IEC 27001:2013
ISO/IEC 27001:2022 replaced the 2013 version, introducing restructured Annex A controls and alignment with ISO Annex SL harmonized structure.
Question 6: Which SOX section requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 802
- Section 906
Correct answer: Section 404
SOX Section 404 requires management to annually assess internal control over financial reporting (ICFR) and have external auditors attest to that assessment.
Question 7: The California Consumer Privacy Act (CCPA) grants California residents the right to opt out of which specific business activity?
- Data encryption practices
- Sale of their personal information (Correct answer)
- Use of cookies on websites
- Storage of biometric data
Correct answer: Sale of their personal information
CCPA gives California residents the right to direct a business to stop selling their personal information to third parties.
Which regulation requires covered entities and business associates to implement safeguards for protected health information (PHI)?