โ† All CSS Flashcard Decks

CSS Compliance & Regulatory Frameworks Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Compliance & Regulatory Frameworks flashcards as text
  1. Which US federal law mandates security controls for federal government information systems and requires FISMA compliance?

    Answer: Federal Information Security Modernization Act (FISMA)

    FISMA requires federal agencies to develop, document, and implement security programs for their information systems, using NIST standards as the framework.

  2. What does the NIST Cybersecurity Framework (CSF) core consist of?

    Answer: Identify, Protect, Detect, Respond, Recover functions

    The NIST CSF organizes security activities into five core functions: Identify, Protect, Detect, Respond, and Recover, providing a common language for managing cybersecurity risk.

  3. Which regulation governs the protection of personal health information (PHI) in the United States?

    Answer: HIPAA (Health Insurance Portability and Accountability Act)

    HIPAA's Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI.

  4. What is the purpose of a System and Organization Controls (SOC 2) audit?

    Answer: Evaluates a service organization's controls for security, availability, processing integrity, confidentiality, and privacy

    SOC 2 reports assess whether a service provider's controls meet the AICPA Trust Service Criteria, particularly relevant for cloud and SaaS providers handling customer data.

  5. Which framework provides a comprehensive set of controls for information security management and is the basis for ISO/IEC 27001 certification?

    Answer: ISO/IEC 27002 (Code of Practice for Information Security Controls)

    ISO/IEC 27002 provides implementation guidance for the information security controls referenced in ISO/IEC 27001, the certifiable ISMS standard.

  6. What does data residency compliance require organizations to ensure?

    Answer: Personal data is stored and processed within specified geographic boundaries mandated by law

    Data residency laws (such as those in the EU, China, and Russia) require that certain data types remain within the country's borders, affecting cloud storage and processing decisions.