Compliance and Auditing Regulatory Frameworks 2 — Questions and Answers
Question 1: Under SOX Section 302, who is primarily responsible for certifying the accuracy of financial reports?
- External auditors
- Board of directors
- CEO and CFO (Correct answer)
- Internal audit team
Correct answer: CEO and CFO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
Question 2: Which HIPAA rule specifically governs the security of electronic protected health information (ePHI)?
- Privacy Rule
- Security Rule (Correct answer)
- Breach Notification Rule
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule establishes national standards to protect electronic protected health information that is created, received, used, or maintained by a covered entity.
Question 3: What is the primary goal of the Federal Information Security Management Act (FISMA)?
- Regulate private sector cybersecurity
- Protect federal information and systems (Correct answer)
- Manage financial institution risk
- Standardize healthcare data
Correct answer: Protect federal information and systems
FISMA requires federal agencies to develop, document, and implement agency-wide information security programs to protect federal information and systems.
Question 4: The Children's Online Privacy Protection Act (COPPA) applies to websites that collect data from children under what age?
- 16
- 18
- 13 (Correct answer)
- 12
Correct answer: 13
COPPA applies to operators of commercial websites and online services directed to children under 13 and requires verifiable parental consent before collecting their personal information.
Question 5: Which regulatory body enforces compliance with SOX for publicly traded US companies?
- FDIC
- SEC (Correct answer)
- FTC
- CFPB
Correct answer: SEC
The Securities and Exchange Commission (SEC) is the primary regulatory body responsible for enforcing Sarbanes-Oxley Act compliance for public companies.
Question 6: The FTC Safeguards Rule requires which type of companies to implement a comprehensive information security program?
- Healthcare organizations
- Non-financial businesses
- Financial institutions (Correct answer)
- Government agencies
Correct answer: Financial institutions
The FTC Safeguards Rule, enacted under GLBA, requires non-banking financial institutions to develop, implement, and maintain a comprehensive information security program.
Under SOX Section 302, who is primarily responsible for certifying the accuracy of financial reports?