IS3230 CHAPTER 4 Flashcards

1
Q

This is a title in the Code of Federal Regulations that deals with Food and Drug Administration (FDA) guidelines on electronic records and signatures. This title requires industries that fall under FDA regs to implement controls and is called ___.

A

21 CFR Part 11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A documented met odd or system of achieving a specific result in an effective efficient manner. It generally takes lessons learned from individuals or groups so that others can complete similar tasks in a more efficient manner is called ___.

A

Best practice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A US law passed in 2000. It requires schools and libraries receiving E-rate funds to filter some Internet content. The primary purpose is to protect minors from obscene or harmful content is called ___.

A

Children’s Internet Protection Act (CIPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Information about a student that an educational institution may release without the written consent of the student is called ___.

A

Directory information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Information about an individual’s health care stored in an electronic format is called ___.

A

Electronic protected health information (EPHI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An act of Congress to protect the privacy of education records and applies to all education institutions receiving funding from the US Dept of Education is called ___.

A

Family Educational Rights and Privacy Act (FERPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An act of Congress that allowed banks, investment firms, and insurance companies to consolidate and also introduced some consumer protections, with one free credit report per year is called ___.

A

Gramm-Leach-Bliley Act (GLBA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A collection of suggestions and best practices relating to a standard or procedure but doesn’t necessarily need to be met but compliance is strongly encouraged is called ___.

A

Guideline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Expanded and updated the civil and criminal penalties and requires notification if any breach causing the disclosure of this occurs is called ___.

A

Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Legislation passed in 1996 that protects the privacy and availability of health care information is called ___.

A

Health Insurance Portability and Accountability Act (HIPAA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This is a standard issued in August 2007 to enforce the standardization of security identification credentials for government employees and contractors. It covers both physical and logical access to government resources is called ___.

A

Homeland Security Presidential Directive 12 (HSPD 12)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A place where the operators vies the data that is received and processed and is connected to a database that gathers information from the RTUs is called ___.

A

Human machine interface (HMI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Created in 1968 to ensure that the North American energy network is secure, adequate, and reliable and is mostly concerned with the creation of guidelines for strong access controls and processes is called ___.

A

North American Electric Reliability Council (NERC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An electronic device used in industrial automation to provide logic and sequencing controls for machinery is called ___.

A

Programmable Logic controllers (PLCs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Any information that concerns health status, health care, or any payment for health care that can be linked to the individual. This includes all of an individual’s medical record and payment history is called ___.

A

Protected health information (PHI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A microprocessor-controlled electronic device that interfaces with objects in the physical world to a distributed control system or SCADA system by transmitting telemetry data to the system and/or altering the state of connected objects based on control messages received from the system is called ___.

A

Remote terminal unit (RTU)

17
Q

Created to protect investors by improving the accuracy and reliability of corporate financial disclosures is called ___.

A

Sarbanes-Oxley (SOX) Act of 2002

18
Q

A collection of requirements that must be met by anyone who performs a given task or works on a a specific system is called ___.

A

Standard

19
Q

Systems utilized to monitor and control telecommunications, water and waste control, energy, and transportation among other industries and utilities is called ___.

A

Supervisory Control and Data Acquisition (SCADA) process control systems

20
Q
  1. In IT, it is imperative that you keep up to date with regulatory compliance laws.
    TRUE OR FALSE
A

TRUE

21
Q
  1. The Gramm-Leach-Blilely Act regulates which industry?
  2. Health Care
  3. Energy
  4. Financial services
  5. Automobile
  6. Education
A

Financial services

22
Q
  1. A company regulated by GLBA is only required to protect against proven security threats, not perceived threats.
    TRUE OR FALSE
A

FALSE

23
Q
  1. HIPAA regulates which industry?
  2. Health Care
  3. Energy
  4. Financial services
  5. Automobile
  6. Education
A

Health Care

24
Q
  1. Protected health information is interpreted very broadly and includes all of an individual’s medical records and payment history?
    TRUE OR FALSE
A

TRUE

25
Q
  1. The HIPAA Security Rule requires a set of ___, technical, and physical safeguards to electronic protected health information (EPHI)
A

Administrative

26
Q
  1. The Sarbanes-Oxley Act regulates all ___ companies.
A

Publicly traded

27
Q
  1. The Family Educational Rights and Privacy Act establishes a student’s right to know the information, location, and purpose of an educational record.
    TRUE OR FALSE
A

TRUE

28
Q
  1. Which regulation defines a standard for electronic records and signatures?
  2. Children’s Internet Protection Act
  3. 21 CFR Part 11
  4. HIPAA
  5. Sarbanes-Oxley
  6. HSPD 12
A

21 CFR Part 11

29
Q
  1. ____ access controls enforce access created by the owner of the object.
A

Discretionary

30
Q
  1. ____ are a collection of suggestions and best practices.
A

Guidelines