IGP Compliance & Risk Management 2 — Questions and Answers
Question 1: Under the NIST Risk Management Framework (RMF), which step involves continuously tracking security controls over time?
- Assess
- Authorize
- Monitor (Correct answer)
- Implement
Correct answer: Monitor
The Monitor step in the NIST RMF involves ongoing assessment of security controls to detect changes that may affect risk posture.
Question 2: A company discovers that a third-party vendor has been improperly handling customer PII. Under a risk management framework, this is best classified as:
- Strategic risk
- Operational risk
- Third-party/supply chain risk (Correct answer)
- Reputational risk
Correct answer: Third-party/supply chain risk
Risks arising from vendor or supplier relationships are classified as third-party or supply chain risk in standard risk frameworks.
Question 3: Which compliance framework is specifically designed to protect cardholder data for organizations that process credit card transactions?
- ISO 27001
- PCI DSS (Correct answer)
- HIPAA
- SOX
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) mandates security controls for any organization that stores, processes, or transmits cardholder data.
Question 4: In risk management, the term 'residual risk' refers to:
- Risk that has been fully eliminated by controls
- Risk remaining after controls have been applied (Correct answer)
- Risk identified but not yet assessed
- Risk transferred to a third party
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after risk treatment or controls have been implemented.
Question 5: The Sarbanes-Oxley Act (SOX) Section 302 primarily requires:
- Annual IT security audits
- CEO and CFO certification of financial statement accuracy (Correct answer)
- Mandatory data breach notification within 72 hours
- Board-level approval for all IT projects
Correct answer: CEO and CFO certification of financial statement accuracy
SOX Section 302 requires senior executives to personally certify the accuracy and completeness of corporate financial reports.
Question 6: When performing a gap analysis for compliance, an organization is primarily trying to:
- Identify the cost of non-compliance penalties
- Compare current state against required compliance standards (Correct answer)
- Rank risks by likelihood and impact
- Document all data flows across the enterprise
Correct answer: Compare current state against required compliance standards
A gap analysis compares an organization's current compliance posture to what is required by a standard or regulation to identify deficiencies.
Question 7: Which type of risk treatment involves purchasing cyber liability insurance?
- Risk avoidance
- Risk mitigation
- Risk acceptance
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Purchasing insurance shifts the financial consequence of a risk to a third party, which is the definition of risk transfer.
Under the NIST Risk Management Framework (RMF), which step involves continuously tracking security controls over time?