Legal and Regulatory Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Legal and Regulatory flashcards as text
Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
Answer: €20 million or 4% of global annual turnover
GDPR's most serious violations can result in fines up to €20 million or 4% of global annual turnover, whichever is higher.
Which US federal law specifically governs the privacy of student education records and limits disclosure without consent?
Answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records held by federally funded institutions.
A CISO discovers that a vendor processes personal data on behalf of the company without a signed Data Processing Agreement. Which GDPR role distinction is most relevant?
Answer: Data controller vs. data processor
GDPR requires a written Data Processing Agreement between a data controller and any data processor handling personal data on its behalf.
Which principle under the GDPR requires that personal data be kept only as long as necessary for its stated purpose?
Answer: Storage limitation
The storage limitation principle mandates that personal data not be retained longer than necessary for the purpose for which it was collected.
An organization operating in California must comply with CCPA. Which right does CCPA grant to consumers regarding personal information held by businesses?
Answer: Right to know, delete, and opt-out of sale
CCPA grants California consumers the right to know what personal information is collected, the right to delete it, and the right to opt-out of its sale.
Under HIPAA, which rule specifically establishes national standards for protecting electronic protected health information (ePHI)?
Answer: Security Rule
HIPAA's Security Rule sets national standards for safeguarding ePHI through administrative, physical, and technical safeguards.
A company's board asks a CISO about Sarbanes-Oxley (SOX) Section 404 requirements. What does Section 404 primarily mandate?
Answer: Management assessment of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with auditor attestation.