🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards
CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance Flashcards
50 question-and-answer cards covering Information Security Frameworks, Law and Compliance as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Information Security Frameworks, Law and Compliance deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
Who is the UK's supervisory authority (regulator) for data protection?
The Information Commissioner's Office (ICO).
What are the maximum administrative fines under the UK GDPR?
Up to £17.5 million or 4% of total annual worldwide turnover (whichever is higher) for the most serious infringements; up to £8.75 million or 2% for lesser infringements.
What is a Data Protection Impact Assessment (DPIA) and when is it required?
A process to identify and minimise data protection risks of a project. Required when processing is likely to result in a high risk to individuals (e.g. large-scale special category data, systematic monitoring, new technologies).
When must an organisation appoint a Data Protection Officer (DPO) under UK GDPR?
When it is a public authority, or its core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category/criminal data.
What are the three main offences created by the Computer Misuse Act 1990?
Section 1: unauthorised access to computer material; Section 2: unauthorised access with intent to commit/facilitate further offences; Section 3: unauthorised acts with intent to impair operation (e.g. malware/DoS).
What additional offence was added to the Computer Misuse Act 1990 covering hacking tools?
Section 3A: making, supplying or obtaining articles (e.g. tools/programs) for use in committing CMA offences.
What is the key concept that determines whether access is an offence under the Computer Misuse Act 1990?
Authorisation - the access or act must be 'unauthorised'. Knowingly exceeding or acting without authorisation is the offence; the user's belief about their authority is relevant to intent.
What is the maximum penalty under Section 3 of the Computer Misuse Act 1990 (unauthorised acts impairing operation)?
Up to 10 years' imprisonment and/or an unlimited fine on indictment (and Section 3ZA covering serious damage can carry life imprisonment).
What is the difference between copyright and a patent in intellectual property law?
Copyright protects the expression of original works (e.g. software code, documents) automatically with no registration. A patent protects novel inventions/processes and must be applied for and granted.
Which UK Act primarily governs copyright, including software?
The Copyright, Designs and Patents Act 1988 (CDPA), under which computer programs are protected as literary works.
How long does copyright generally last for literary works (including software) in the UK?
For literary, dramatic, musical and artistic works: the life of the author plus 70 years. (Software is treated as a literary work.)
What are the four main types of intellectual property protection?
Copyright, patents, trade marks, and registered/unregistered designs (with trade secrets/confidential information also protected separately).
What is a software licence and why does it matter for compliance?
A legal agreement granting permission to use software under defined terms; using software outside licence terms (e.g. over-deployment or unlicensed copies) infringes copyright and breaches compliance, risking legal/financial penalties.
What does the Investigatory Powers Act 2016 (the 'Snoopers' Charter') regulate?
The powers of public authorities to carry out interception, communications data acquisition and equipment interference, and obligations on communication providers to retain communications data.
What does the Regulation of Investigatory Powers Act 2000 (RIPA) cover relevant to organisations?
It regulates interception of communications and lawful monitoring; organisations monitoring employee communications must have lawful basis, policy and notice (see also Lawful Business Practice Regulations).
What does the Network and Information Systems (NIS) Regulations 2018 require?
Operators of essential services (OES) and relevant digital service providers (RDSP) to take appropriate security measures and report significant incidents, improving the resilience of critical network and information systems.
What is the Freedom of Information Act 2000, and who does it apply to?
It gives the public a right of access to recorded information held by UK public authorities; authorities must respond to requests (generally within 20 working days), subject to exemptions.
What is the difference between the FOIA 2000 and the UK GDPR/DPA 2018 regarding access?
FOIA gives anyone access to recorded information held by public authorities (any subject). UK GDPR/DPA gives individuals access to their own personal data (a Subject Access Request).
Within the ISO/IEC 27000 family, what is the difference between ISO/IEC 27001 and ISO/IEC 27002?
ISO/IEC 27001 is the certifiable specification for an ISMS (requirements). ISO/IEC 27002 is a code of practice giving guidance on the implementation of information security controls (not certifiable).
What does ISO/IEC 27001 certification demonstrate?
That an organisation has an independently audited Information Security Management System (ISMS) meeting the standard's requirements, with a risk-based approach to managing information security.
What is the UK Government's Cyber Essentials scheme?
A government-backed certification scheme defining five basic technical controls (firewalls, secure configuration, user access control, malware protection, security/patch update management) to protect against common cyber attacks; Cyber Essentials Plus adds independent technical verification.
What is the purpose of compliance monitoring and security audit within an ISMS?
To independently verify that controls are implemented, effective and complied with - providing assurance to management, identifying gaps/non-conformities and driving continual improvement.
What is the difference between an internal audit and an external (independent) audit?
An internal audit is performed by the organisation's own staff (first/second-party) for self-assurance and improvement. An external audit is performed by an independent third party (e.g. certification body) providing impartial assurance.
What are the key drivers for records management and a records retention schedule?
Legal/regulatory requirements, business/operational need, and accountability. A retention schedule defines how long records are kept and ensures secure, timely disposal - balancing storage limitation (e.g. UK GDPR) against legal retention obligations.
What this deck covers
The Information Security Frameworks, Law and Compliance deck follows the CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance syllabus — 3 chapters and 11 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.7 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 186 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Information Security Frameworks, Law and Compliance flashcards FAQ
How many Information Security Frameworks, Law and Compliance flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?
50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these CISMP (Certificate in Information Security Management Principles) flashcards free?
Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.
What do the Information Security Frameworks, Law and Compliance cards cover?
They follow the CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance syllabus — 3 chapters and 11 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.