SDI Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority once detected?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires that personal data breaches be reported to the supervisory authority within 72 hours of becoming aware of the breach.
Question 2: Which U.S. federal law requires healthcare organizations and their business associates to implement safeguards for protected health information (PHI)?
- SOX
- HIPAA (Correct answer)
- FERPA
- FISMA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) mandates administrative, physical, and technical safeguards for PHI handled by covered entities and business associates.
Question 3: A service desk analyst inadvertently emails a customer's account details to the wrong recipient. Under data protection principles, this most directly violates which principle?
- Data minimization
- Purpose limitation
- Integrity and confidentiality (Correct answer)
- Storage limitation
Correct answer: Integrity and confidentiality
Sending personal data to an unauthorized recipient violates the integrity and confidentiality (security) principle, which requires appropriate protection against unauthorized disclosure.
Question 4: ISO/IEC 20000-1 is specifically relevant to IT service management because it:
- Defines penetration testing methodology
- Sets requirements for an IT service management system (Correct answer)
- Establishes software development lifecycle controls
- Mandates cybersecurity incident response plans
Correct answer: Sets requirements for an IT service management system
ISO/IEC 20000-1 specifies the requirements for establishing, implementing, maintaining, and improving an IT service management system (SMS).
Question 5: PCI DSS compliance is required for organizations that:
- Process publicly traded stock transactions
- Store, process, or transmit cardholder data (Correct answer)
- Provide cloud hosting services to financial firms
- Employ more than 500 people in the payments industry
Correct answer: Store, process, or transmit cardholder data
PCI DSS (Payment Card Industry Data Security Standard) applies to any entity that stores, processes, or transmits cardholder data, regardless of size or number of transactions.
Question 6: Which SOX section is most directly relevant to IT controls because it requires management to assess internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 409
- Section 802
Correct answer: Section 404
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, which directly implicates IT general controls.
Question 7: When a service desk receives a legal hold notice, what is the correct immediate action regarding relevant electronic records?
- Delete records older than 12 months to reduce legal exposure
- Suspend normal data retention schedules and preserve all related records (Correct answer)
- Encrypt affected records and restrict access to senior management only
- Transfer records to an external legal team for safekeeping
Correct answer: Suspend normal data retention schedules and preserve all related records
A legal hold requires the suspension of normal retention and deletion schedules to preserve all potentially relevant records for litigation or investigation.
Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority once detected?