← All CIAM Flashcard Decks

Compliance Standards Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Standards flashcards as text
  1. Which NIST SP 800-53 control family directly governs identification and authentication requirements?

    Answer: IA – Identification and Authentication

    The IA control family in NIST SP 800-53 covers organizational identification and authentication policies, including multi-factor authentication.

  2. Under CCPA, which right allows California consumers to request that a business delete their personal information?

    Answer: Right to Delete

    CCPA's Right to Delete allows consumers to request deletion of their personal information collected by a business, subject to certain exceptions.

  3. ISO 27001 Annex A control A.9.2 specifically addresses which IAM process?

    Answer: User access management (provisioning and deprovisioning)

    ISO 27001 Annex A.9.2 covers user access management, including registration, deregistration, and review of access rights.

  4. A quarterly access review where managers certify their team's entitlements is best described as which compliance control?

    Answer: User access recertification (UAR)

    User Access Recertification (UAR) is a periodic review process where data owners or managers certify that access rights remain appropriate.

  5. Which regulation requires financial institutions to implement a comprehensive information security program and is enforced by the FTC?

    Answer: GLBA Safeguards Rule

    The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to protect customer financial information through a written security program.

  6. In a GDPR context, what is the maximum timeframe for notifying supervisory authorities after discovering a personal data breach?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

  7. Which CIS Control directly maps to managing access based on the principle of least privilege?

    Answer: CIS Control 6 – Access Control Management

    CIS Control 6 focuses on Access Control Management, including least privilege, limiting administrative rights, and centralizing access management.