โ† All RCC Flashcard Decks

RCC Data Privacy and Information Security Compliance Flashcards

6 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 RCC Data Privacy and Information Security Compliance flashcards as text
  1. The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into which core functions?

    Answer: Identify, Protect, Detect, Respond, Recover

    The NIST CSF organizes cybersecurity practices into five core functions: Identify, Protect, Detect, Respond, and Recover, providing a risk-based approach to managing cybersecurity.

  2. An organization stores cardholder data and processes credit card transactions. Which standard governs its data security compliance obligations?

    Answer: PCI DSS (Payment Card Industry Data Security Standard)

    PCI DSS is the mandated security standard for any organization that stores, processes, or transmits cardholder data, requiring specific technical and operational controls.

  3. What is 'pseudonymization' in a data privacy compliance context?

    Answer: Replacing direct identifiers with artificial identifiers so data cannot be attributed to a specific individual without additional information

    Pseudonymization replaces identifying information with a pseudonym, reducing privacy risk while still allowing data to be re-identified when combined with separately stored key information.

  4. Under US federal law, which agency is primarily responsible for enforcing consumer data privacy and security in most industries?

    Answer: The Federal Trade Commission (FTC)

    The FTC enforces Section 5 of the FTC Act, which prohibits unfair or deceptive practices, and has broad authority over consumer data privacy and security across most industry sectors.

  5. What is the primary compliance purpose of an 'incident response plan' in information security?

    Answer: To provide a structured process for detecting, containing, investigating, and recovering from security incidents

    An incident response plan establishes pre-defined roles, procedures, and communication protocols to ensure that security incidents are managed quickly and effectively, limiting regulatory and reputational damage.

  6. An organization transfers European Union residents' personal data to a US entity. Under GDPR frameworks, which mechanism is commonly used to legitimize this transfer?

    Answer: Standard Contractual Clauses (SCCs) approved by the European Commission

    Standard Contractual Clauses (SCCs) are legally approved data transfer mechanisms that contractually obligate the US recipient to protect EU personal data to GDPR standards.