Compliance & Regulatory Standards Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance & Regulatory Standards flashcards as text
Which regulation requires federal agencies to conduct Privacy Impact Assessments (PIAs) before developing or procuring IT systems that collect personally identifiable information?
Answer: E-Government Act of 2002
Section 208 of the E-Government Act of 2002 requires federal agencies to conduct and publish Privacy Impact Assessments for systems that collect, maintain, or disseminate PII.
The NIST Cybersecurity Framework (CSF) core consists of five functions. Which function focuses on detecting cybersecurity events?
Answer: Detect
The 'Detect' function of the NIST CSF defines activities to identify the occurrence of a cybersecurity event in a timely manner.
Under Executive Order 14028 (Improving the Nation's Cybersecurity, 2021), federal agencies must adopt which security architecture approach?
Answer: Zero Trust Architecture
EO 14028 directed federal agencies to advance toward Zero Trust Architecture, requiring CISA and NIST to develop guidance for this transition.
An agency's ATO has expired and the system remains in operation. What is the correct term for this status?
Answer: Operating without authorization (OWA)
When a system's ATO expires and it continues operating, it is considered to be operating without authorization (OWA), which represents unacceptable risk under FISMA.
Which NIST publication defines the Controlled Unclassified Information (CUI) security requirements specifically for nonfederal organizations?
Answer: NIST SP 800-171 Rev 2
NIST SP 800-171 Rev 2 provides 110 security requirements organized into 14 families for protecting CUI in nonfederal systems and organizations.
A financial institution discovers it has been sharing customer data with a third-party marketer without proper authorization. Which regulation is most directly violated?
Answer: Gramm-Leach-Bliley Act (GLBA)
The GLBA Privacy Rule restricts financial institutions from disclosing nonpublic personal information to nonaffiliated third parties without providing customers notice and opt-out opportunity.
Under the RMF, which document formally records the results of security control assessments and identifies deficiencies?
Answer: Security Assessment Report (SAR)
The Security Assessment Report (SAR) documents the assessor's findings and recommendations resulting from the security control assessment, including identified weaknesses.