GRC Compliance Standards & Regulatory Requirements 5 — Questions and Answers
Question 1: Which compliance framework introduced the concept of 'continuous monitoring' as a key component of the Risk Management Framework (RMF)?
- ISO/IEC 27001
- NIST SP 800-37 (Correct answer)
- COBIT 5
- PCI DSS v4.0
Correct answer: NIST SP 800-37
NIST SP 800-37 (RMF) incorporates continuous monitoring as Step 6 of its six-step process to maintain ongoing awareness of security and privacy posture.
Question 2: Under GDPR, a Data Protection Impact Assessment (DPIA) is MANDATORY when processing is likely to result in:
- Any use of cookies on a website
- High risk to the rights and freedoms of natural persons (Correct answer)
- Processing data of more than 1,000 individuals
- Cross-border data transfers within the EU
Correct answer: High risk to the rights and freedoms of natural persons
Article 35 of GDPR requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of individuals, particularly for systematic profiling or sensitive data processing.
Question 3: Which Dodd-Frank Act provision created the Consumer Financial Protection Bureau (CFPB) to regulate consumer financial products?
- Title I
- Title VII
- Title X (Correct answer)
- Title XIV
Correct answer: Title X
Title X of the Dodd-Frank Wall Street Reform and Consumer Protection Act established the Consumer Financial Protection Bureau (CFPB).
Question 4: In the context of PCI DSS v4.0, what new approach was introduced alongside the traditional compliance approach?
- Risk-based approach
- Customized approach (Correct answer)
- Maturity model approach
- Zero-trust approach
Correct answer: Customized approach
PCI DSS v4.0 introduced the 'Customized Approach' as an alternative that allows organizations to achieve security objectives using their own controls rather than following prescriptive requirements.
Question 5: Which regulation governs the privacy of student education records at institutions receiving federal funding?
- COPPA
- HIPAA
- FERPA (Correct answer)
- GLBA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at federally funded educational institutions.
Question 6: When a company processes personal data of EU residents from a third country, GDPR requires an 'adequacy decision' OR which alternative transfer mechanism?
- A non-disclosure agreement signed by both parties
- Appropriate safeguards such as Standard Contractual Clauses (SCCs) (Correct answer)
- Registration with the local EU data protection authority
- Annual security audits reviewed by the European Data Protection Board
Correct answer: Appropriate safeguards such as Standard Contractual Clauses (SCCs)
In the absence of an adequacy decision, GDPR Article 46 requires appropriate safeguards such as Standard Contractual Clauses (SCCs), binding corporate rules, or approved codes of conduct.
Question 7: Which CMMC level requires an organization to have a documented and institutionalized cybersecurity program aligned to ALL 110 NIST SP 800-171 practices?
- CMMC Level 1
- CMMC Level 2 (Correct answer)
- CMMC Level 3
- CMMC Level 4
Correct answer: CMMC Level 2
CMMC Level 2 requires implementation of all 110 practices from NIST SP 800-171 and a documented cybersecurity program, with third-party assessments required for critical programs.
Which compliance framework introduced the concept of 'continuous monitoring' as a key component of the Risk Management Framework (RMF)?