Compliance and Auditing Regulatory Frameworks 1 — Questions and Answers
Question 1: Which US federal law requires public companies to establish internal controls over financial reporting?
- Sarbanes-Oxley Act (SOX) (Correct answer)
- Gramm-Leach-Bliley Act
- Dodd-Frank Act
- Securities Exchange Act
Correct answer: Sarbanes-Oxley Act (SOX)
The Sarbanes-Oxley Act of 2002 mandates that public companies implement and attest to internal controls over financial reporting under Section 404.
Question 2: Which regulation governs the protection of personal health information in the United States?
- FERPA
- HIPAA (Correct answer)
- COPPA
- GLBA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets standards for protecting sensitive patient health information from being disclosed without consent.
Question 3: The Payment Card Industry Data Security Standard (PCI DSS) is maintained by which organization?
- Federal Reserve
- PCI Security Standards Council (Correct answer)
- NIST
- Department of Treasury
Correct answer: PCI Security Standards Council
The PCI Security Standards Council, founded by major card brands, develops and maintains PCI DSS to protect cardholder data.
Question 4: Which US law requires financial institutions to protect consumers' personal financial information?
- HIPAA
- SOX
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- CAN-SPAM Act
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices and safeguard sensitive consumer data.
Question 5: NIST SP 800-53 provides security and privacy controls for which type of organizations?
- Private sector corporations only
- Federal information systems and organizations (Correct answer)
- International banks
- Healthcare providers only
Correct answer: Federal information systems and organizations
NIST SP 800-53 provides a catalog of security and privacy controls specifically for federal information systems and organizations as required by FISMA.
Question 6: Which framework is commonly used by US organizations to assess and improve cybersecurity risk management?
- ISO 27001
- COBIT 5
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ITIL v4
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework provides a policy framework of computer security guidance for US organizations to assess and improve their ability to prevent, detect, and respond to cyberattacks.
Which US federal law requires public companies to establish internal controls over financial reporting?