GRC Compliance Standards & Regulatory Requirements 3 — Questions and Answers
Question 1: Which compliance framework is specifically designed to secure controlled unclassified information (CUI) in non-federal systems and organizations?
- FedRAMP
- NIST SP 800-171 (Correct answer)
- CMMC
- FISMA
Correct answer: NIST SP 800-171
NIST SP 800-171 provides security requirements for protecting CUI in nonfederal information systems, often required by defense contractors.
Question 2: Under HIPAA, a Business Associate Agreement (BAA) is required when a third party does which of the following?
- Sells software to a covered entity
- Creates, receives, maintains, or transmits PHI on behalf of a covered entity (Correct answer)
- Provides physical security for a hospital building
- Manufactures medical devices
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is required whenever a third-party business associate creates, receives, maintains, or transmits PHI while performing services for a covered entity.
Question 3: Which PCI DSS requirement mandates that cardholder data environments must restrict inbound and outbound traffic to only that which is necessary?
- Requirement 1 — Install and maintain network security controls (Correct answer)
- Requirement 3 — Protect stored account data
- Requirement 6 — Develop and maintain secure systems
- Requirement 10 — Log and monitor all access
Correct answer: Requirement 1 — Install and maintain network security controls
PCI DSS Requirement 1 focuses on network security controls, including firewalls and router configurations that restrict unnecessary traffic to and from the cardholder data environment.
Question 4: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to designate a qualified individual responsible for overseeing what?
- Anti-money laundering (AML) programs
- Customer information security program (Correct answer)
- Credit risk assessment processes
- Securities trading compliance
Correct answer: Customer information security program
The GLBA Safeguards Rule requires financial institutions to designate a qualified individual to oversee, implement, and enforce the information security program.
Question 5: Under GDPR, which legal basis allows an organization to process personal data without consent when it is necessary to fulfill a contract with the data subject?
- Legitimate interests
- Legal obligation
- Contractual necessity (Correct answer)
- Vital interests
Correct answer: Contractual necessity
Article 6(1)(b) of GDPR permits processing personal data without consent when it is necessary for the performance of a contract to which the data subject is a party.
Question 6: COBIT 2019 is primarily used to govern and manage which domain?
- Physical security of data centers
- Enterprise information and technology (Correct answer)
- Human resources compliance
- Supply chain risk management
Correct answer: Enterprise information and technology
COBIT 2019 is an internationally recognized framework for the governance and management of enterprise information and technology (EGIT).
Question 7: Which regulation enacted after the 2001 financial scandals requires CEOs and CFOs to personally certify the accuracy of financial reports?
- Dodd-Frank Act
- Sarbanes-Oxley Act Section 302 (Correct answer)
- Securities Exchange Act Section 10(b)
- Investment Advisers Act
Correct answer: Sarbanes-Oxley Act Section 302
SOX Section 302 requires principal executive and financial officers to personally certify the accuracy and completeness of periodic SEC financial reports.
Which compliance framework is specifically designed to secure controlled unclassified information (CUI) in non-federal systems and organizations?