MOD 23 Flashcards

1
Q

What is it called when you conform to a rule such as a specification, policy, standard or law?

A

Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does GRC stand for?

A

Governance, Risk Management, and Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which audit is a comprehensive review of an organization adherence to regulatory guidelines?

A

Compliance audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What council is responsible for the creation of credit card companies?

A

PCI Security Standards Council

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What has a set of requirements for maintaining a secure environment?

A

PCI-DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Noncompliance to the PCI-DSS results in ________.

A

penalties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can the PCI enforce laws?

A

No!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How are audits done?

A

Qualified Security Assessor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which SOX Section states that companies must publish information on scope, adequacy, and effectiveness of internal controls and procedures?

A

SOX Section 404

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which SOX Section states that signing officers (CEO, CFO) must certify that they’ve evaluated internal controls and report any fraud?

A

SOX Section 302

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Internal control is often done in accordance with what?

A

COBIT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a framework for GRC developed by ISACA?

A

COBIT 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the COBIT standards?

A

ISO 38500, 20000, 27000, 31000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What applies to PHI (Protected Health Information) and covers health plans and health care providers?

A

HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is anything that can identify a usser with health information?

A

PHI (Protected Health Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 3 requirements from HIPPA?

A

Administrative, Physical, Technical

17
Q

Which Act protects the privacy of student educational records?

A

FERPA

18
Q

What is disclosable from FERPA?

A

directory information (name, address, phone, birthday, etc.)

19
Q

What protects government information, operations, or assets?

A

FISMA

20
Q

Which Act gave administration to Homeland Security (DHS) and amended the Office of Management and Budget?

A

FISMA Act (2014)

21
Q

What is the first step of NIST Risk Management Framework?

A

Categorize

22
Q

What is the last step of NIST Risk Management Framework?

A

Monitor

23
Q

Which Act allowed banks, security companies and insurance companies to be the same institution?

A

Gramm-Leach-Bliley Act (GLBA)

24
Q

Which Act focuses on anti-bribery and accounting for US companies doing business outside of the country?

A

Foreign Corrupt Practices Act (FCPA)

25
Q

What was previously the AICPA/CICA Privacy Network that has accepted privacy principles?

A

Generally Accepted Privacy Principles (GAPP)

26
Q

Which rule sets how financial institutions and creditors develop identity theft protection programs?

A

Red Flags Rule

27
Q

The FTC can seek fine up to ________ per violation(maximum) in federal court.

A

$3,500

28
Q

What sets guidelines and assists courts in setting fines for criminal regulatory cases?

A

US Sentencing Commission (USCC)

29
Q

What is the median salary for Compliance Officer jobs?

A

$64,000

30
Q

Compliance Officer jobs will grow _____% through 2024

A

3.3%