โ† All CAP Flashcard Decks

Compliance & Regulatory Standards Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Regulatory Standards flashcards as text
  1. Which federal law requires agencies to report major information security incidents to Congress and OMB within a specific timeframe?

    Answer: FISMA

    FISMA requires federal agencies to report major incidents to Congress and OMB, establishing accountability for information security.

  2. Under NIST SP 800-53, which control family specifically addresses audit and accountability requirements?

    Answer: Audit and Accountability (AU)

    The AU (Audit and Accountability) control family in NIST SP 800-53 covers audit log generation, review, and retention requirements.

  3. Which Privacy Act requirement mandates that agencies publish notice of their records systems in the Federal Register?

    Answer: System of Records Notice (SORN)

    A System of Records Notice (SORN) must be published in the Federal Register before an agency can create or modify a system that retrieves records by personal identifier.

  4. A healthcare organization subject to HIPAA must conduct a risk analysis under which specific rule?

    Answer: HIPAA Security Rule

    The HIPAA Security Rule requires covered entities to conduct a thorough assessment of the potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability.

  5. Under FedRAMP, what is the minimum assessment frequency for systems with a Moderate impact level?

    Answer: Continuous monitoring with annual authorization review

    FedRAMP Moderate systems require continuous monitoring with an annual authorization review to maintain an Authorization to Operate (ATO).

  6. Which OMB circular establishes the requirement for agencies to develop and maintain an information security program?

    Answer: OMB Circular A-130

    OMB Circular A-130 establishes policy for the planning, budgeting, governance, acquisition, and management of federal information, including information security programs.

  7. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement which type of program?

    Answer: Information Security Program

    The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.