BPA Compliance, Auditing & Risk Management Flashcards
6 cards from real BPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 BPA Compliance, Auditing & Risk Management flashcards as text
In BPA risk management, which strategy involves transferring the financial impact of a risk to a third party?
Answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to another party, typically through insurance or contractual agreements with vendors.
A BPA audit finds that a bot has been accessing data beyond its required scope. This violates which security and compliance principle?
Answer: Least privilege
The least privilege principle requires that bots and users only have access to the minimum data and systems necessary to perform their function.
Which document defines the expectations for how quickly an automated process must be restored after a failure, from a compliance perspective?
Answer: Recovery Time Objective (RTO) documented in the BCP/DRP
The Recovery Time Objective (RTO), documented in a Business Continuity Plan or Disaster Recovery Plan, specifies the maximum tolerable downtime for a process.
For a BPA process that handles payment card data, which compliance standard mandates specific controls?
Answer: PCI-DSS
PCI-DSS (Payment Card Industry Data Security Standard) defines mandatory security controls for any system that stores, processes, or transmits cardholder data.
What is the purpose of a compliance matrix in a BPA implementation project?
Answer: To map each regulatory requirement to specific process controls, verifying coverage
A compliance matrix cross-references applicable regulations with implemented controls to demonstrate and verify that all requirements are addressed.
During a BPA audit, the auditor requests evidence of 'control effectiveness.' What type of evidence best demonstrates this?
Answer: Logs, screenshots, and reports showing that controls functioned as intended over a defined period
Control effectiveness is proven through objective, time-stamped evidence such as system logs and reports that confirm controls operated correctly.