โ† All CAP Flashcard Decks

Compliance & Regulatory Standards Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Regulatory Standards flashcards as text
  1. An organization must report a breach of unsecured PHI to HHS. If the breach affects 500 or more individuals, what is the notification deadline?

    Answer: Within 60 days of discovery

    HIPAA Breach Notification Rule requires covered entities to notify HHS of breaches affecting 500+ individuals within 60 calendar days of discovering the breach.

  2. Which NIST publication provides guidance specifically on security and privacy controls for federal information systems and organizations?

    Answer: NIST SP 800-53

    NIST SP 800-53 is the primary catalog of security and privacy controls for federal information systems, organized into families and with multiple control baselines.

  3. The Children's Online Privacy Protection Act (COPPA) applies to websites collecting personal information from children under what age?

    Answer: 13

    COPPA applies to operators of commercial websites and online services directed to children under 13, requiring parental consent before collecting personal information.

  4. A system security plan (SSP) is required under which regulatory mandate for federal agencies?

    Answer: FISMA

    FISMA requires federal agencies to develop and maintain an SSP that describes the security requirements of the system and the controls in place to meet those requirements.

  5. Under NIST SP 800-53 Rev 5, the Supply Chain Risk Management (SR) control family was introduced. Which control requires organizations to develop and implement a supply chain risk management plan?

    Answer: SR-2

    SR-2 (Supply Chain Risk Management Plan) requires organizations to develop, document, and disseminate a plan for managing supply chain risks to organizational systems.

  6. The Sarbanes-Oxley Act (SOX) Section 404 requires which of the following?

    Answer: Management assessment of internal controls over financial reporting

    SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.

  7. Which standard provides a framework for information security management systems (ISMS) and is used for international compliance certification?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 is the international standard specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS, and organizations can obtain certification against it.