← All CSC Flashcard Decks

Cybersecurity Regulations & Legal Frameworks Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cybersecurity Regulations & Legal Frameworks flashcards as text
  1. A healthcare organization shares patient billing data with a third-party payment processor. Under HIPAA, the payment processor is classified as a:

    Answer: Business associate

    A third party that performs functions involving PHI on behalf of a covered entity is classified as a business associate and must sign a Business Associate Agreement (BAA).

  2. SOX Section 404 specifically requires management and external auditors to report on the effectiveness of:

    Answer: Internal controls over financial reporting

    SOX Section 404 mandates that management assess and auditors attest to the effectiveness of internal controls over financial reporting (ICFR).

  3. Which GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes?

    Answer: Purpose limitation

    The purpose limitation principle under GDPR Article 5(1)(b) states that personal data must be collected for specified, explicit, and legitimate purposes only.

  4. Under PCI DSS, which entities are required to undergo an annual on-site assessment by a Qualified Security Assessor (QSA)?

    Answer: Level 1 merchants processing over 6 million transactions annually

    PCI DSS Level 1 merchants, those processing more than 6 million card transactions per year, are required to undergo annual on-site QSA assessments.

  5. The Computer Fraud and Abuse Act (CFAA) defines 'protected computer' as:

    Answer: Any computer used in or affecting interstate commerce or communication

    The CFAA defines 'protected computer' broadly to include any computer used in or affecting interstate or foreign commerce or communication, covering virtually all internet-connected systems.

  6. Which regulation requires maritime and port facility operators to implement cybersecurity measures as part of facility security plans?

    Answer: Coast Guard NVIC 01-20

    Coast Guard Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on cybersecurity for maritime industry and incorporates NIST CSF requirements.

  7. Under California's CCPA, the right to opt-out allows consumers to direct businesses to stop:

    Answer: Selling their personal information to third parties

    CCPA's right to opt-out specifically allows consumers to direct businesses to stop selling their personal information to third parties.