🇬🇧 Chartered IT Professional (CITP) · flashcards

Chartered IT Professional (CITP) Law, Regulation and Governance Flashcards

52 question-and-answer cards covering Law, Regulation and Governance as it is examined in Chartered IT Professional (CITP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

52Cards in deck
24Free preview
9Syllabus topics
~269Chars per answer
FreePrice

24 sample cards from the Law, Regulation and Governance deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. How long does copyright last for literary works (including software) in the UK?

    For literary, dramatic, musical and artistic works (software is protected as a literary work), copyright lasts for the life of the author plus 70 years from the end of the year of their death.

  2. Does software require registration to be protected by copyright in the UK?

    No. Under the Copyright, Designs and Patents Act 1988, copyright arises automatically when an original work (including source code) is created and fixed; there is no registration system for copyright in the UK.

  3. What conditions must an invention satisfy to be patentable in the UK?

    It must be new (novel), involve an inventive step (non-obvious), be capable of industrial application, and not fall within excluded categories. Notably, computer programs 'as such' and mathematical methods are excluded, though a program producing a technical effect may be patentable.

  4. How long does a UK patent last and what is required to maintain it?

    A UK patent lasts up to 20 years from the filing date, subject to payment of annual renewal fees (typically from the 5th year onward).

  5. What is the difference between a registered and an unregistered trade mark?

    A registered trade mark (R symbol) is granted by the IPO, lasts 10 years and is indefinitely renewable, giving statutory exclusive rights. An unregistered mark (TM symbol) is protected only through the common law tort of 'passing off', which requires proving goodwill, misrepresentation and damage.

  6. In an employment context, who typically owns the IP in software created by an employee?

    Under the CDPA 1988, where a work is made by an employee in the course of their employment, the employer is the first owner of any copyright (and similarly for patents under the Patents Act 1977), unless a contract states otherwise. Contractors/freelancers usually retain IP unless assigned in writing.

  7. What essential elements must be present to form a legally binding contract under English law?

    Offer, acceptance, consideration, intention to create legal relations, and capacity (and the contract must be for a lawful purpose with certainty of terms).

  8. What is the difference between a contractual warranty and a condition?

    A condition is a fundamental term going to the root of the contract; its breach entitles the innocent party to terminate and claim damages. A warranty is a minor term; its breach entitles the innocent party only to damages, not termination.

  9. What is a limitation of liability clause, and what types of liability cannot lawfully be excluded?

    A limitation clause caps or restricts the damages one party can recover. Under the Unfair Contract Terms Act 1977, liability for death or personal injury caused by negligence cannot be excluded, and liability for fraud cannot be excluded; other exclusions must satisfy a test of reasonableness.

  10. Distinguish between liquidated damages and a penalty clause in English contract law.

    Liquidated damages are a genuine pre-estimate of loss agreed in advance and are enforceable. A penalty clause imposes a sum out of all proportion to any legitimate interest and is intended to punish; it is unenforceable. The modern test is whether the clause is a proportionate protection of a legitimate interest.

  11. What is the difference between contractual liability and tortious liability (negligence)?

    Contractual liability arises from breach of an agreed term between parties to a contract. Tortious liability (e.g. negligence) arises independently of any contract, from a breach of a duty of care owed in law, where the breach causes foreseeable harm to another.

  12. What three elements must a claimant prove to establish negligence?

    1) The defendant owed the claimant a duty of care; 2) the defendant breached that duty (fell below the reasonable standard); 3) the breach caused reasonably foreseeable damage (causation and remoteness).

  13. What is COBIT and what is its purpose?

    COBIT (Control Objectives for Information and Related Technologies), developed by ISACA, is an IT governance and management framework. It helps organisations align IT with business goals, manage IT-related risk, ensure regulatory compliance, and create value through governance and management objectives.

  14. What is the difference between IT governance and IT management?

    IT governance is the responsibility of the board/executives — it sets direction, evaluates options, and monitors performance to ensure IT delivers value and manages risk (the 'what' and 'why'). IT management plans, builds, runs and monitors activities to achieve those directions (the 'how').

  15. What does ITIL provide and what is its focus?

    ITIL (Information Technology Infrastructure Library) is a framework of best practices for IT Service Management (ITSM). It focuses on aligning IT services with business needs across the service lifecycle/value system, covering practices such as incident, problem, change and service level management.

  16. What is ISO/IEC 27001 and what is its core deliverable?

    ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). Its core requirement is establishing a risk-based ISMS with documented controls; organisations can be certified, and Annex A provides a catalogue of security controls (a Statement of Applicability documents which are used).

  17. What is the COSO framework primarily used for?

    The COSO (Committee of Sponsoring Organizations) framework provides guidance on internal control, enterprise risk management (ERM) and fraud deterrence. Its Internal Control–Integrated Framework defines five components: control environment, risk assessment, control activities, information & communication, and monitoring.

  18. What is the 'three lines' model in governance and risk management?

    First line: operational management who own and manage risks directly. Second line: risk and compliance functions that oversee and advise on risk. Third line: internal audit providing independent assurance to the governing body. It clarifies roles in managing and assuring risk.

  19. What is the Network and Information Systems (NIS) Regulations 2018 about?

    The NIS Regulations 2018 impose cybersecurity and incident-reporting duties on operators of essential services (e.g. energy, transport, water, health, digital infrastructure) and relevant digital service providers, to improve the resilience of critical network and information systems.

  20. What is PCI DSS and to whom does it apply?

    The Payment Card Industry Data Security Standard is a set of security requirements that applies to any organisation that stores, processes or transmits cardholder data. It is a contractual/industry standard (not statute) enforced by the card brands, covering requirements such as encryption, access control and network security.

  21. What are PECR and how do they relate to UK GDPR?

    The Privacy and Electronic Communications Regulations 2003 (PECR) sit alongside UK GDPR and govern electronic marketing (email, SMS, calls), cookies and similar technologies, and communications security. They require, for example, consent for non-essential cookies and for most electronic marketing.

  22. What duties does the Equality Act 2010 place on organisations, and what are the protected characteristics?

    The Equality Act 2010 prohibits discrimination and requires reasonable adjustments for disabled people. The nine protected characteristics are: age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation.

  23. What accessibility standard underpins UK public sector website obligations, and what conformance level is required?

    The Web Content Accessibility Guidelines (WCAG) 2.1 (or 2.2) at conformance level AA. The Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 require public sector websites and apps to meet WCAG AA and publish an accessibility statement.

  24. What are the four guiding principles (POUR) of the Web Content Accessibility Guidelines (WCAG)?

    Perceivable, Operable, Understandable, and Robust. Content and interfaces must be presentable to users in ways they can perceive, components must be operable, information and operation must be understandable, and content must be robust enough to work with assistive technologies.

What this deck covers

The Law, Regulation and Governance deck follows the Chartered IT Professional (CITP) Law, Regulation and Governance syllabus — 3 chapters and 9 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.3 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 269 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Law, Regulation and Governance flashcards FAQ

How many Law, Regulation and Governance flashcards are in this Chartered IT Professional (CITP) deck?

52 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Chartered IT Professional (CITP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 52-card deck is free inside the Examius app.

What do the Law, Regulation and Governance cards cover?

They follow the Chartered IT Professional (CITP) Law, Regulation and Governance syllabus — 3 chapters and 9 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.