Legal and Regulatory Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Legal and Regulatory flashcards as text
Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age?
Answer: 13
COPPA requires verifiable parental consent before collecting, using, or disclosing personal information from children under age 13.
A multinational company undergoes an M&A transaction. From a legal and compliance standpoint, which due diligence area is most critical from a CISO's perspective?
Answer: Assessing inherited cybersecurity liabilities and regulatory obligations
During M&A due diligence, the acquiring company must assess inherited cybersecurity vulnerabilities, data breaches, regulatory violations, and compliance obligations of the target.
Which US executive order significantly shaped federal cybersecurity requirements for critical infrastructure and established information-sharing between the private sector and government?
Answer: EO 14028
Executive Order 14028 (2021) on Improving the Nation's Cybersecurity modernized federal security standards, mandated zero trust architecture, and enhanced software supply chain security.
The concept of 'privacy by design' requires organizations to embed privacy protections into systems from the outset. Which GDPR article explicitly codifies this requirement?
Answer: Article 25
GDPR Article 25 mandates Data Protection by Design and by Default, requiring controllers to integrate data protection into processing activities from the design stage.
Under securities law, a CISO learns of a material cybersecurity incident affecting a publicly traded company. The SEC's 2023 cybersecurity disclosure rules require public disclosure within how many business days?
Answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.
A CISO must understand e-discovery obligations. Under the Federal Rules of Civil Procedure (FRCP), electronically stored information (ESI) must be preserved when which obligation arises?
Answer: When litigation is reasonably anticipated
The litigation hold duty to preserve ESI arises when litigation is reasonably anticipated, before a lawsuit is actually filed or a subpoena received.
Which legal doctrine protects confidential communications between an attorney and client, and may shield legal counsel's cybersecurity assessments from disclosure in litigation?
Answer: Attorney-client privilege
Attorney-client privilege protects confidential communications between attorney and client made for the purpose of seeking or providing legal advice, potentially including security assessments.