🇺🇸 Certified Information Security Manager (CISM) · flashcards

Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management Flashcards

51 question-and-answer cards covering Legal, Regulatory, and Compliance Management as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
9Syllabus topics
~226Chars per answer
FreePrice

24 sample cards from the Legal, Regulatory, and Compliance Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is an attestation engagement in a compliance context?

    An attestation is an examination in which an independent party (e.g., a CPA firm) issues an opinion or conclusion about whether a subject matter conforms to specified criteria, providing assurance to third parties.

  2. What is the difference between certification and attestation?

    Certification is formal confirmation that something meets a defined standard (e.g., ISO 27001 certificate) issued by an accredited body; attestation is an independent opinion on whether a subject matter meets stated criteria (e.g., a SOC 2 report).

  3. What is FedRAMP and what does it authorize?

    FedRAMP (Federal Risk and Authorization Management Program) standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by U.S. federal agencies. Authorizations come at Low, Moderate, and High impact levels.

  4. What is control mapping (crosswalking) in compliance?

    Control mapping is the process of aligning controls from one framework or requirement to equivalent controls in another, so that a single control implementation can satisfy multiple regulatory or standard requirements.

  5. What is harmonization of compliance requirements and why is it valuable?

    Harmonization rationalizes overlapping requirements from multiple laws, regulations, and frameworks into a unified set of controls. It reduces duplication, cost, and audit fatigue while improving consistency ('comply once, satisfy many').

  6. What is a Common Controls Framework (or unified control framework)?

    A consolidated internal framework that merges controls from multiple external authorities (e.g., HIPAA, PCI DSS, ISO 27001) into one normalized set, each control mapped back to its source requirements.

  7. What is the Secure Controls Framework (SCF) known for?

    The SCF is a free 'meta-framework' that provides a comprehensive catalog of controls pre-mapped to hundreds of laws, regulations, and standards, supporting harmonization and crosswalking across jurisdictions.

  8. What is the difference between compliance monitoring and a point-in-time audit?

    Compliance monitoring is the ongoing, continuous tracking of control effectiveness and adherence; a point-in-time audit is a periodic, formal examination of controls as of a specific date. Monitoring detects drift between audits.

  9. What is continuous controls monitoring (CCM)?

    CCM is the automated, ongoing collection and analysis of control evidence and metrics to detect control failures, exceptions, or noncompliance in near real time, rather than waiting for periodic audits.

  10. What is the difference between an internal audit and an external audit?

    Internal audits are conducted by the organization's own staff to provide management assurance and improve processes; external audits are performed by independent third parties to provide objective assurance to regulators, customers, or the board.

  11. In auditing, what is the difference between a finding and a recommendation?

    A finding is a documented condition where actual practice deviates from criteria (a control gap or noncompliance); a recommendation is the auditor's suggested corrective action to remediate the finding.

  12. What is a compliance gap analysis?

    A gap analysis compares the organization's current control state against required controls (from a regulation or framework) to identify deficiencies that must be remediated to achieve compliance.

  13. What is the purpose of a corrective action plan (CAP) or POA&M?

    A Corrective Action Plan (or Plan of Action and Milestones) documents identified deficiencies, the remediation steps, responsible owners, resources, and target completion dates to close compliance gaps.

  14. What is the difference between an SLA, an OLA, and a UC?

    An SLA (Service Level Agreement) is between provider and customer; an OLA (Operational Level Agreement) is internal between supporting teams; a UC (Underpinning Contract) is with an external supplier/subcontractor. All define service expectations.

  15. What key security elements should be included in a third-party contract or SLA?

    Right-to-audit clauses, security/compliance requirements, data protection and confidentiality obligations, breach notification timelines, subcontractor (fourth-party) restrictions, liability/indemnification, and termination/data return provisions.

  16. What is a right-to-audit clause?

    A contractual provision allowing the customer (or its representatives/regulators) to audit or assess the vendor's security controls and compliance, ensuring ongoing assurance over outsourced services.

  17. What is third-party (vendor) risk management and why does it matter for compliance?

    It is the process of identifying, assessing, and monitoring risks introduced by suppliers and service providers. It matters because regulatory liability for data protection often cannot be outsourced—the organization remains accountable for its vendors.

  18. What is fourth-party risk?

    Risk arising from the subcontractors and suppliers of your direct (third-party) vendors. Organizations must understand and manage these downstream dependencies, often via contractual flow-down requirements.

  19. What is a Business Associate Agreement (BAA) under HIPAA?

    A BAA is a contract required between a HIPAA covered entity and a business associate (vendor handling ePHI) that obligates the business associate to safeguard the PHI and comply with applicable HIPAA requirements.

  20. What is the purpose of a Data Processing Agreement (DPA) under GDPR?

    A DPA is a legally required contract between a controller and processor (Article 28) that specifies the subject, duration, nature, and purpose of processing, plus the processor's obligations to protect personal data and assist the controller.

  21. What are the core principles of professional ethics in ISACA's Code of Professional Ethics?

    Support adherence to standards and procedures, maintain due diligence and competence, serve stakeholders' interests lawfully and honestly, maintain confidentiality/privacy, and inform stakeholders of audit results—maintaining objectivity and avoiding conflicts of interest.

  22. Why is auditor independence and objectivity essential to professional conduct?

    Independence (freedom from conflicts) and objectivity (unbiased mindset) ensure that audit and assurance conclusions are credible and trustworthy; their absence undermines the value of the assurance and can constitute an ethics violation.

  23. What is the ethical obligation regarding confidentiality of information obtained during an audit?

    Professionals must protect the confidentiality of information acquired in the course of their duties and not use it for personal benefit or disclose it without proper authority unless legally required to do so.

  24. What should a security manager do when a legal/regulatory requirement conflicts with organizational policy or another jurisdiction's law?

    Escalate to legal counsel and senior management, document the conflict, and seek a risk-based resolution—generally applying the most stringent applicable requirement or a formally accepted, documented exception while ensuring lawful conduct.

What this deck covers

The Legal, Regulatory, and Compliance Management deck follows the Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management syllabus — 3 chapters and 9 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 226 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Legal, Regulatory, and Compliance Management flashcards FAQ

How many Legal, Regulatory, and Compliance Management flashcards are in this Certified Information Security Manager (CISM) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Security Manager (CISM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Legal, Regulatory, and Compliance Management cards cover?

They follow the Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management syllabus — 3 chapters and 9 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.