← All ACL Flashcard Decks

Compliance & Regulatory Frameworks Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance & Regulatory Frameworks flashcards as text
  1. An organization must document ACL rule justifications as part of a compliance audit. Which regulatory framework most explicitly requires that firewall and ACL rules be accompanied by documented business justifications?

    Answer: PCI DSS

    PCI DSS Requirement 1.2.1 explicitly requires that every ACL and firewall rule restricting inbound and outbound traffic be accompanied by a documented business justification.

  2. A security team reviews ACL logs to meet NIST SP 800-53 AU-2 (Auditable Events) requirements. Which log entries are most critical to capture from ACL devices?

    Answer: Both permitted and denied connection attempts including source IP, destination IP, port, protocol, and timestamp

    AU-2 requires logging both allowed and denied events; capturing complete ACL flow data (source, destination, port, protocol, time) enables auditing and forensic analysis.

  3. During a PCI DSS audit, a QSA finds that ACL rules have not been reviewed in 18 months. Which specific requirement is violated?

    Answer: Requirement 1.2.5 — All permitted services, protocols, and ports must be identified and reviewed at least every six months

    PCI DSS Requirement 1.2.5 mandates that all permitted services, protocols, and ports in firewall and ACL rule sets be reviewed at least every six months.

  4. Under the NIST Privacy Framework, which ACL control practice aligns with the GOVERN-P function's CT.PO-P1 (Policies, Processes, and Procedures)?

    Answer: Establishing and maintaining formal ACL governance policies that define ownership, change control, and periodic review schedules

    CT.PO-P1 requires organizations to establish policies for managing privacy controls including network access; formal ACL governance directly implements this requirement.

  5. A financial institution subject to FFIEC guidance implements ACLs for their online banking infrastructure. Which FFIEC-recommended practice specifically addresses ACL rule hygiene?

    Answer: Regularly reviewing and removing unnecessary ACL rules to minimize the attack surface of internet-facing systems

    FFIEC IT Examination Handbooks recommend regular ACL reviews to eliminate unnecessary rules and reduce the attack surface, particularly for internet-facing financial systems.

  6. An organization implements Zero Trust Architecture (ZTA) as guided by NIST SP 800-207. How does this change their approach to ACLs compared to traditional perimeter-based compliance?

    Answer: ZTA requires per-session ACL enforcement based on identity, device posture, and context rather than relying on network location as a trust signal

    NIST SP 800-207 ZTA shifts ACL enforcement from network-perimeter trust to per-session dynamic policies based on identity, device health, and request context regardless of network location.

  7. A healthcare organization implements ACLs to support their HIPAA Risk Management Plan. Which action demonstrates ongoing compliance rather than point-in-time compliance?

    Answer: Establishing a continuous ACL review cycle tied to risk assessments, updating rules as threats and infrastructure evolve

    HIPAA requires an ongoing risk management process; ACL rules must be continuously reviewed and updated as part of the required periodic risk analysis and mitigation activities.