Legal and Regulatory Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Legal and Regulatory flashcards as text
Which international standard provides a framework for information security management systems (ISMS) and is most commonly cited in regulatory compliance contexts?
Answer: ISO 27001
ISO 27001 is the international standard specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS.
The Computer Fraud and Abuse Act (CFAA) primarily criminalizes which type of activity?
Answer: Unauthorized access to protected computers
The CFAA makes it a federal crime to access a protected computer without authorization or in excess of authorized access.
Under GDPR, a data breach must be reported to the supervisory authority within what timeframe after the controller becomes aware of it?
Answer: 72 hours
GDPR Article 33 requires data controllers to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Which US federal law established the framework for protecting critical infrastructure information shared between the private sector and the government?
Answer: CISA 2015
The Cybersecurity Information Sharing Act (CISA) of 2015 established protections and procedures for sharing cyber threat indicators between private entities and the federal government.
A CISO must ensure compliance with PCI DSS. Which entity mandates PCI DSS compliance for organizations handling cardholder data?
Answer: Payment Card Industry Security Standards Council (PCI SSC)
The PCI SSC, founded by major card brands, develops and manages PCI DSS, which applies to all entities that store, process, or transmit cardholder data.
The EU NIS2 Directive expanded the scope of cybersecurity obligations compared to the original NIS Directive. Which new obligation does NIS2 specifically add for top management?
Answer: Personal liability of executives for cybersecurity failures
NIS2 holds top management personally liable and can impose temporary bans on managerial roles for cybersecurity negligence causing serious incidents.
Under GLBA (Gramm-Leach-Bliley Act), which rule requires financial institutions to develop, implement, and maintain a comprehensive information security program?
Answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a written comprehensive information security program to protect customer financial information.