Compliance Frameworks Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Frameworks flashcards as text
Which framework uses a maturity model with five levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) to assess cybersecurity processes?
Answer: CMMI
CMMI (Capability Maturity Model Integration) defines five maturity levels used to benchmark and improve organizational processes including security.
Under the FedRAMP authorization process, which impact level applies to federal systems where breach could cause serious adverse effects?
Answer: High
FedRAMP High impact level applies to systems where unauthorized disclosure could cause severe or catastrophic adverse effects on federal operations or national security.
A company performing a gap analysis against ISO 27001 identifies missing controls. What document defines the scope of controls selected for implementation?
Answer: Statement of Applicability (SoA)
The Statement of Applicability (SoA) lists all ISO 27001 Annex A controls, indicating which are applicable, implemented, or excluded with justification.
Which CIS Control focuses on continuous vulnerability management through scanning and remediation?
Answer: CIS Control 7 — Continuous Vulnerability Management
CIS Control 7 specifically addresses continuous vulnerability management, requiring organizations to regularly scan for and remediate vulnerabilities.
FISMA requires federal agencies to categorize information systems using which standard?
Answer: FIPS 199
FIPS 199 provides the standards for security categorization of federal information and information systems based on potential impact.
Which HIPAA rule establishes national standards for the protection of electronically protected health information (ePHI)?
Answer: HIPAA Security Rule
The HIPAA Security Rule specifically addresses the protection of ePHI through administrative, physical, and technical safeguards.
An analyst discovers that the organization's cloud provider holds a shared responsibility for compliance. Under PCI DSS, who is ultimately accountable for cardholder data protection?
Answer: The merchant (covered entity)
Under PCI DSS, the merchant (covered entity) retains ultimate accountability for cardholder data protection regardless of what a cloud provider manages.