← All CIAM Flashcard Decks

Compliance Standards Flashcards

7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Standards flashcards as text
  1. An organization subject to NERC CIP must implement electronic access controls for which type of assets?

    Answer: Bulk Electric System (BES) Cyber Systems

    NERC CIP standards apply to Bulk Electric System (BES) Cyber Systems and require strict electronic access controls to protect critical infrastructure.

  2. Which compliance requirement is primarily satisfied by implementing privileged access workstations (PAWs) for administrators?

    Answer: Privileged account isolation and protection (e.g., NIST SP 800-53 AC-6)

    PAWs satisfy privileged access isolation requirements by providing a dedicated, hardened environment for administrative tasks, aligning with NIST AC-6 and similar controls.

  3. Under SOC 2 Trust Service Criteria, which criteria category covers logical and physical access controls?

    Answer: Logical and Physical Access Controls (CC6)

    SOC 2 Common Criteria CC6 specifically addresses logical and physical access controls as part of the Common Criteria related to logical and physical access.

  4. A healthcare organization must ensure that only authorized workforce members access ePHI based on their job function. Which HIPAA concept does this describe?

    Answer: Minimum necessary standard

    The HIPAA Minimum Necessary standard requires covered entities to limit access to ePHI to only what is needed for the workforce member's job function.

  5. Which provision of the EU AI Act has direct implications for identity verification systems used in high-risk AI applications?

    Answer: High-risk AI system requirements including human oversight and logging (Title III)

    Title III of the EU AI Act imposes requirements on high-risk AI systems—including biometric identification—such as human oversight, logging, and accuracy standards.

  6. During a PCI DSS audit, an assessor finds that shared generic accounts are used for database administration. Which requirement is violated?

    Answer: Requirement 8 – Identify users and authenticate access

    PCI DSS Requirement 8.2 prohibits the use of shared, group, or generic accounts, requiring unique IDs for all users including administrators.

  7. Which FISMA requirement mandates that federal agencies continuously monitor the security controls of their information systems?

    Answer: Continuous monitoring program

    FISMA requires agencies to implement ongoing continuous monitoring programs to maintain real-time awareness of security control effectiveness.