Compliance & Regulatory Standards Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance & Regulatory Standards flashcards as text
Which Executive Order directed the development of the Cybersecurity Framework (CSF) by NIST?
Answer: EO 13636
Executive Order 13636 (Improving Critical Infrastructure Cybersecurity, 2013) directed NIST to develop the Cybersecurity Framework.
Under the Privacy Act of 1974, which of the following is NOT a right afforded to individuals?
Answer: Right to financial compensation for all unauthorized disclosures
While the Privacy Act provides civil remedies, it does not guarantee financial compensation for all unauthorized disclosures—damages must be proven and intentional violations established.
NIST SP 800-37 defines the RMF. Which step immediately follows the Categorize step?
Answer: Select
In the RMF, after categorizing the system (Step 1), the next step is to Select appropriate security controls (Step 2) based on the categorization.
A contractor handling Controlled Unclassified Information (CUI) for DoD must comply primarily with which regulation?
Answer: NIST SP 800-171
NIST SP 800-171 specifies the security requirements for protecting CUI in nonfederal systems and organizations, making it the primary compliance standard for DoD contractors.
Which standard defines the requirements for Payment Card Industry Data Security?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the global standard mandating security controls for organizations that store, process, or transmit cardholder data.
Under FISMA, which role is responsible for authorizing the operation of an information system?
Answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior official with the authority to accept the risk of operating an information system and formally issue an Authorization to Operate (ATO).
Which compliance framework is specifically required for federal government cloud service providers and uses a 'do once, use many times' approach?
Answer: FedRAMP
FedRAMP standardizes cloud security assessments so that cloud service providers undergo one assessment that can be reused (authorized) by multiple federal agencies.