Industry Regulations & Compliance Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Industry Regulations & Compliance flashcards as text
Under HIPAA, what is the maximum civil penalty per violation category when the covered entity demonstrates willful neglect and fails to correct the violation?
Answer: $1,900,000
HIPAA civil penalties for willful neglect not corrected cap at $1,919,173 per violation category per calendar year (adjusted for inflation from the original $1,500,000).
Which U.S. federal law specifically governs the interception of electronic communications and sets standards for lawful access to stored electronic data?
Answer: Electronic Communications Privacy Act (ECPA)
The ECPA of 1986 governs wiretapping, electronic surveillance, and access to stored communications, making it central to digital forensic legal compliance.
A forensic examiner discovers evidence on a corporate server that may relate to insider trading. Which regulatory body's guidelines would most directly govern the handling and reporting of this financial evidence?
Answer: SEC
The SEC (Securities and Exchange Commission) has primary jurisdiction over insider trading violations and governs evidence handling in related investigations.
What does the 'chain of custody' requirement primarily ensure under Federal Rules of Evidence (FRE) Rule 901?
Answer: Evidence can be authenticated as what it is claimed to be
FRE Rule 901 requires authentication — demonstrating that evidence is what the proponent claims it is — which chain of custody documentation directly supports.
Under GDPR, when conducting digital forensic investigations involving EU citizens' data, what is the maximum fine for serious violations?
Answer: €20 million or 4% of global annual turnover
GDPR's highest tier fines are €20 million or 4% of total global annual turnover, whichever is higher, for the most serious infringements.
Which standard framework provides a set of controls specifically designed for protecting cardholder data in payment systems, directly relevant when examining retail point-of-sale breaches?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) defines requirements for protecting cardholder data and is the primary framework for payment system breach investigations.
In a U.S. federal investigation, what legal authority does a forensic examiner need to search and seize digital evidence from a third-party cloud provider?
Answer: A search warrant or court order under 18 U.S.C. § 2703
Under the Stored Communications Act (18 U.S.C. § 2703), law enforcement must obtain a warrant, court order, or subpoena depending on the type and age of stored data.