← All CCP Flashcard Decks

Compliance, Legal, & Ethical Issues Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance, Legal, & Ethical Issues flashcards as text
  1. The EU-US Data Privacy Framework replaced which previous mechanism that was invalidated by the Schrems II ruling?

    Answer: Privacy Shield

    The EU-US Privacy Shield was invalidated by the Court of Justice of the EU in the Schrems II decision due to US surveillance law concerns.

  2. Under HIPAA, a covered entity discovers a breach affecting 600 individuals. What is the notification deadline to the Secretary of HHS?

    Answer: Within 60 days of year-end, or immediately if over 500

    Breaches affecting 500+ individuals in a state must be reported to HHS within 60 days of discovery; smaller breaches are reported in annual logs within 60 days of year-end.

  3. Which concept in cybersecurity law holds that an organization may be liable for failing to implement reasonable security measures even without a specific breach occurring?

    Answer: Negligence

    Negligence in cybersecurity law means failing to exercise reasonable care in protecting systems and data, which can establish liability independent of an actual breach.

  4. A company collects children's data through a mobile app. Which US federal law imposes parental consent requirements?

    Answer: COPPA

    The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13.

  5. Which PCI DSS requirement specifically addresses the protection of stored cardholder data?

    Answer: Requirement 3 – Protect stored cardholder data

    PCI DSS Requirement 3 mandates that organizations protect stored cardholder data through encryption, masking, and data minimization practices.

  6. An employee uses company resources to run a personal cryptocurrency mining operation. Which ethical violation has primarily occurred?

    Answer: Unauthorized use of resources

    Using organizational resources for personal financial gain without authorization violates the ethical obligation to use employer resources only for authorized purposes.

  7. Which legal theory allows a plaintiff to sue for damages when a data breach results from a defendant's failure to meet an industry standard of care?

    Answer: Negligence per se

    Negligence per se applies when a defendant violates a statute or regulation that establishes the standard of care, and that violation causes harm.