โ† All CIAM Flashcard Decks

Compliance Standards Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Standards flashcards as text
  1. Under HIPAA's Security Rule, which safeguard category requires covered entities to implement access control policies for electronic PHI?

    Answer: Technical safeguards

    HIPAA Technical Safeguards mandate access controls, audit controls, integrity controls, and transmission security for ePHI systems.

  2. Which PCI DSS requirement specifically addresses the need to assign a unique ID to each person with computer access?

    Answer: Requirement 8

    PCI DSS Requirement 8 covers identification and authentication of access to system components, including assigning unique IDs.

  3. SOX Section 404 compliance primarily requires organizations to do which of the following related to IAM?

    Answer: Assess and report on internal controls over financial reporting

    SOX Section 404 mandates management assessment and auditor attestation of internal controls over financial reporting, including access controls.

  4. The GDPR principle of 'data minimization' most directly influences which IAM practice?

    Answer: Least privilege access provisioning

    Data minimization aligns with least privilege by ensuring users only access the minimum data necessary for their role.

  5. Which compliance framework introduced the concept of 'segregation of duties' as a key control for preventing fraud in financial systems?

    Answer: Sarbanes-Oxley Act (SOX)

    SOX heavily emphasizes segregation of duties as an internal control to prevent a single individual from controlling all aspects of a financial transaction.

  6. Under FedRAMP, cloud service providers must implement identity controls based on which underlying framework?

    Answer: NIST SP 800-53

    FedRAMP uses NIST SP 800-53 security controls as its foundation, including the AC (Access Control) and IA (Identification and Authentication) control families.

  7. A company must prove that terminated employees lose system access within 24 hours. Which compliance activity best demonstrates this?

    Answer: Joiner-mover-leaver process audit log review

    Reviewing joiner-mover-leaver (JML) process audit logs shows the timestamps of deprovisioning actions relative to termination events.