โ† All CSC Flashcard Decks

Security Controls & Compliance Implementation Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Controls & Compliance Implementation flashcards as text
  1. A healthcare organization must ensure that a business associate handles PHI according to HIPAA requirements. What document formalizes this obligation?

    Answer: Business Associate Agreement (BAA)

    A Business Associate Agreement (BAA) is required by HIPAA when a covered entity shares PHI with a third-party business associate, specifying permissible uses and required safeguards.

  2. In the context of the NIST Risk Management Framework (RMF), what happens during the 'Authorize' step?

    Answer: A senior official accepts residual risk and grants an Authorization to Operate (ATO)

    During the Authorize step, an Authorizing Official reviews the security authorization package and formally accepts residual risk by granting or denying an ATO.

  3. Which of the following BEST describes the scope of GDPR applicability?

    Answer: It applies to any organization that processes personal data of EU residents, regardless of where the organization is located

    GDPR has extraterritorial reach and applies to any organization worldwide that processes personal data of individuals located in the EU, regardless of the organization's location.

  4. A security team uses a vulnerability scanner and discovers a critical vulnerability in a web application. According to common compliance frameworks, what is the typical required remediation timeframe for critical vulnerabilities?

    Answer: Within 30 days

    Most compliance frameworks, including PCI DSS, require critical vulnerabilities to be remediated within 30 days of discovery.

  5. What is the primary purpose of configuration baselines in compliance programs?

    Answer: To establish a known secure state against which systems are measured and deviations detected

    Configuration baselines define the approved secure configuration state, enabling organizations to detect and respond to unauthorized or non-compliant configuration changes.

  6. Under ISO 27001, what is the role of the Statement of Applicability (SoA)?

    Answer: It documents which Annex A controls are applicable, included, or excluded with justification

    The SoA is a required ISO 27001 document that maps each Annex A control to the organization, stating applicability, implementation status, and justification for exclusions.

  7. Which type of access control model enforces access decisions based on security labels assigned to both subjects and objects?

    Answer: Mandatory Access Control (MAC)

    MAC uses security labels (classification levels and categories) assigned to subjects and objects, with access enforced by the system based on policy rather than owner discretion.