Compliance Standards Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Standards flashcards as text
An enterprise must demonstrate compliance with GDPR's accountability principle regarding IAM. Which artifact best satisfies this?
Answer: A documented Records of Processing Activities (RoPA) including access control measures
The Records of Processing Activities (RoPA) documents data flows and protective measures including access controls, directly evidencing GDPR accountability compliance.
Which NIST Cybersecurity Framework function most closely aligns with user access provisioning and deprovisioning processes?
Answer: Protect
The Protect function of the NIST CSF covers identity management and access control, including provisioning and deprovisioning of user access.
Under CMMC Level 2, which practice domain requires organizations to control access to CUI based on least privilege?
Answer: Access Control (AC)
CMMC Level 2 Access Control (AC) practices require limiting system access to authorized users and implementing least privilege for CUI protection.
A regulated bank must ensure that a loan officer cannot both initiate and approve the same transaction. Which IAM control enforces this?
Answer: Segregation of duties (SoD)
Segregation of Duties (SoD) prevents a single individual from having conflicting roles, such as both initiating and approving financial transactions.
Which ISO 27001 control requires organizations to review access rights at regular intervals?
Answer: A.9.2.5 – Review of user access rights
ISO 27001 control A.9.2.5 requires asset owners to review user access rights at regular intervals and after any personnel changes.
A company processing EU citizen data from a U.S. data center must rely on which mechanism to legally transfer data under GDPR?
Answer: EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs)
International data transfers from the EU to the U.S. require a valid transfer mechanism such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
Which HITRUST CSF control category maps most directly to identity lifecycle management including onboarding and offboarding?
Answer: 09 – Access Control
HITRUST CSF Control Category 09 (Access Control) encompasses identity lifecycle management including user provisioning, modification, and deprovisioning.