ExamGecko
Home Home / ISC / CCSP
Question list
Search
Search

Question 232 - CCSP discussion

Report
Export

Although the United States does not have a single, comprehensive privacy and regulatory framework, a number of specific regulations pertain to types of data or populations.

Which of the following is NOT a regulatory system from the United States federal government?

A.
HIPAA
Answers
A.
HIPAA
B.
SOX
Answers
B.
SOX
C.
FISMA
Answers
C.
FISMA
D.
PCI DSS
Answers
D.
PCI DSS
Suggested answer: D

Explanation:

The Payment Card Industry Data Security Standard (PCI DSS) pertains to organizations that handle credit card transactions and is an industry-regulatory standard, not a governmental one. The Sarbanes-Oxley Act (SOX) was passed in 2002 and pertains to financial records and reporting, as well as transparency requirements for shareholders and other stakeholders. The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 and pertains to data privacy and security for medical records. FISMA refers to the Federal Information Security Management Act of 2002 and pertains to the protection of all US federal government IT systems, with the exception of national security systems.

asked 18/09/2024
Marco Romani
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first