Regulatory Frameworks & Compliance Flashcards
7 cards from real Software Testing practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
A tester working on a medical device must ensure software meets ISO 14971 requirements. What does this standard primarily address?
Answer: Risk management for medical devices
ISO 14971 is the international standard for risk management of medical devices, requiring identification, evaluation, and control of risks throughout the software lifecycle.
Under NIST SP 800-53, which testing activity satisfies the 'CA-8' control for penetration testing of federal information systems?
Answer: Conducting authorized simulated attacks to identify exploitable vulnerabilities
NIST SP 800-53 CA-8 requires organizations to conduct penetration testing to identify weaknesses that could be exploited by adversaries.
What distinguishes 'qualification testing' from standard system testing in aerospace and defense software contexts?
Answer: Qualification testing demonstrates the software meets its stated requirements for regulatory approval
Qualification testing provides formal, documented evidence that software meets specified requirements for regulatory or contractual approval, not just internal quality checks.
In SOC 2 (Service Organization Control 2) compliance, which testing validates the 'Availability' trust service criterion?
Answer: Testing that systems meet agreed-upon uptime commitments and recovery objectives
SOC 2 Availability testing verifies that systems are operational and accessible as committed, typically through uptime measurement and disaster recovery testing.
Which testing challenge is MOST unique to compliance testing compared to standard functional testing?
Answer: Providing legally defensible documentation that requirements were met
Compliance testing must produce auditable, legally defensible evidence that regulatory requirements were verified, not just confirm the software works.
A financial services firm must comply with FINRA Rule 3110. From a software testing perspective, what does this primarily require?
Answer: Supervision and review of electronic communications and trading activity records
FINRA Rule 3110 requires firms to establish supervisory systems and verify that systems correctly capture, store, and make available all required communications and records.
What is the role of an 'independent verification and validation (IV&V)' team in safety-critical software testing?
Answer: To provide an unbiased assessment of software quality separate from the development organization
IV&V teams provide objective, independent evaluation of safety-critical software, reducing the risk of bias when developers verify their own work.