โ† All CAP Flashcard Decks

Federal Compliance and Regulatory Requirements Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Federal Compliance and Regulatory Requirements flashcards as text
  1. Which regulation governs the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems?

    Answer: NIST SP 800-171

    NIST SP 800-171 establishes requirements for protecting CUI in nonfederal systems and organizations, particularly for DoD contractors.

  2. What does the term 'Controlled Unclassified Information' (CUI) refer to?

    Answer: Information the government requires safeguarding per law, regulation, or policy, but is not classified

    CUI is sensitive government information that requires protection but does not meet the threshold for national security classification.

  3. Which federal law requires agencies to conduct Privacy Impact Assessments for new information technology systems?

    Answer: E-Government Act of 2002

    Section 208 of the E-Government Act of 2002 mandates PIAs before agencies develop or procure new IT systems that collect PII.

  4. CISA plays which primary role in federal cybersecurity compliance?

    Answer: Coordinates federal civilian cybersecurity defense and leads incident response

    CISA (Cybersecurity and Infrastructure Security Agency) leads the national effort to defend civilian federal networks and coordinate incident response.

  5. The Federal Risk and Authorization Management Program (FedRAMP) standardizes security authorizations for which type of systems?

    Answer: Cloud computing products and services used by federal agencies

    FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by the federal government.

  6. Which OMB memorandum introduced the 'Assume Breach' mentality and required agencies to adopt zero trust architecture?

    Answer: OMB M-22-09

    OMB M-22-09 established a federal zero trust architecture strategy requiring agencies to meet specific zero trust security goals.