โ† All SSP Flashcard Decks

Legal & Ethical Compliance Flashcards

7 cards from real SSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Legal & Ethical Compliance flashcards as text
  1. A security practitioner is asked by an executive to share confidential employee investigation records with HR without a formal request. The correct action is to:

    Answer: Require a formal written request following established protocols

    Confidential investigation records must be shared only through formal, documented requests to maintain chain of custody and legal defensibility.

  2. Which legal concept holds an employer responsible for wrongful acts committed by employees within the scope of their employment?

    Answer: Respondeat superior

    Respondeat superior is the legal doctrine under which employers are vicariously liable for employee actions performed within the scope of employment.

  3. Under GDPR, what is the maximum timeframe to notify supervisory authorities of a personal data breach that poses risk to individuals?

    Answer: 72 hours

    GDPR Article 33 requires that personal data breaches posing risk to individuals be reported to the supervisory authority within 72 hours of discovery.

  4. A security professional who witnesses evidence being destroyed during an ongoing investigation should:

    Answer: Document what was observed and immediately report to legal counsel

    Observing evidence destruction must be immediately documented and reported to legal counsel to preserve legal options and comply with spoliation rules.

  5. The concept of 'duty of care' in security management primarily means:

    Answer: Taking reasonable precautions to protect persons from foreseeable harm

    Duty of care obligates security professionals to take reasonable measures to protect individuals from harm that is reasonably foreseeable.

  6. Which act requires federal agencies and contractors to implement minimum security standards for information systems?

    Answer: Federal Information Security Modernization Act (FISMA)

    FISMA requires federal agencies and their contractors to develop, document, and implement security programs to protect federal information systems.

  7. What is the primary ethical principle violated when a security consultant recommends a product from a vendor in which they hold undisclosed financial interest?

    Answer: Conflict of interest

    An undisclosed financial interest in a recommended vendor creates a conflict of interest, violating professional ethical standards.

Legal & Ethical Compliance Flashcards โ€” SSP Study Cards with Answers