GRC Compliance Standards & Regulatory Requirements 4 — Questions and Answers
Question 1: An organization storing sensitive data in AWS wants to achieve FedRAMP authorization. Which step must come FIRST in the formal authorization process?
- Obtain a Provisional Authorization to Operate (P-ATO) from the JAB
- Complete a System Security Plan (SSP) (Correct answer)
- Conduct penetration testing
- Hire a Third Party Assessment Organization (3PAO)
Correct answer: Complete a System Security Plan (SSP)
The FedRAMP authorization process begins with completing a System Security Plan (SSP) that documents all security controls implemented in the cloud system.
Question 2: Under NERC CIP standards, which standard addresses Physical Security of BES Cyber Systems?
- NERC CIP-005
- NERC CIP-006 (Correct answer)
- NERC CIP-007
- NERC CIP-010
Correct answer: NERC CIP-006
NERC CIP-006 establishes requirements for physical security plans to protect BES (Bulk Electric System) Cyber Systems from unauthorized physical access.
Question 3: Which element is NOT one of the three pillars of the EU-US Data Privacy Framework that replaced Privacy Shield?
- Data minimization requirements
- Binding corporate rules for transfers (Correct answer)
- Redress mechanisms for EU individuals
- Safeguards on US government access to data
Correct answer: Binding corporate rules for transfers
The EU-US Data Privacy Framework's three pillars address data protection obligations, redress mechanisms, and US government surveillance safeguards — not binding corporate rules.
Question 4: SOC 2 Type II reports differ from Type I reports primarily because Type II reports cover:
- A broader set of Trust Services Criteria
- The design AND operating effectiveness of controls over a period of time (Correct answer)
- Only the security and availability principles
- External auditor qualifications and independence
Correct answer: The design AND operating effectiveness of controls over a period of time
SOC 2 Type II reports evaluate both the design suitability and the operating effectiveness of controls over a minimum review period (typically 6–12 months).
Question 5: Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age?
- 12
- 13 (Correct answer)
- 16
- 18
Correct answer: 13
COPPA requires verifiable parental consent before collecting, using, or disclosing personal information from children under 13 years of age.
Question 6: Which ISO standard specifically addresses privacy information management systems (PIMS) and is designed to complement ISO/IEC 27001?
- ISO/IEC 27018
- ISO/IEC 27701 (Correct answer)
- ISO/IEC 29100
- ISO/IEC 27002
Correct answer: ISO/IEC 27701
ISO/IEC 27701 extends ISO/IEC 27001 and 27002 to include privacy requirements, providing a framework for establishing, implementing, and maintaining a PIMS.
Question 7: A healthcare organization suffers a breach affecting 600 patients in one state. Under HIPAA's Breach Notification Rule, what is the notification deadline to HHS?
- Within 24 hours
- Within 30 days of discovery
- Within 60 days of the end of the calendar year (Correct answer)
- Within 60 days of discovery
Correct answer: Within 60 days of the end of the calendar year
For breaches affecting fewer than 500 individuals, covered entities must notify HHS within 60 days after the end of the calendar year in which the breach was discovered.
An organization storing sensitive data in AWS wants to achieve FedRAMP authorization.
Which step must come FIRST in the formal authorization process?