nerdexam
(ISC)2

CCSP · Question #689

Which of the following is NOT a major regulatory framework?

The correct answer is D. FIPS 140-2. FIPS 140-2 (Federal Information Processing Standard) is a US government technical standard for validating cryptographic modules - it defines security requirements for cryptographic hardware and software. It is a security standard, not a regulatory compliance framework. PCI DSS is

Submitted by weili_xi· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following is NOT a major regulatory framework?

Options

  • APCI DSS
  • BHIPAA
  • CSOX
  • DFIPS 140-2

How the community answered

(37 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    95% (35)

Explanation

FIPS 140-2 (Federal Information Processing Standard) is a US government technical standard for validating cryptographic modules - it defines security requirements for cryptographic hardware and software. It is a security standard, not a regulatory compliance framework. PCI DSS is a regulatory standard for payment card industry data security, HIPAA is a US law governing healthcare information privacy and security, and SOX (Sarbanes-Oxley) is a US law governing financial reporting and corporate governance. Those three impose legal or industry compliance obligations; FIPS 140-2 is a technical certification standard.

Topics

#Regulatory frameworks#Compliance#Data protection laws#Security standards

Community Discussion

No community discussion yet for this question.

Full CCSP Practice