The information life cycle recognizes that data has different value,...
Opting-in means an individual makes an active, affirmative indication...
True or false? All incidents are breaches, but not all breaches are...
Information security provides physical, technical and administrative...
True or false? When communicating about a breach, an organization...
Can you identify the five phases of a privacy program audit?
Which best describes the disadvantages of a centralized privacy...
Why does an organization need a privacy program? Identify the number 3...
In the U.S., many industries have sector-specific privacy-related laws...
A privacy policy is generally an internal document that is addressed...
How do information security and privacy teams work in concert, so that...
Control types and categories. Information security provides physical,...
Information security provides physical, technical and administrative...
Privacy risks. In 2006, Daniel Solove authored an article entitled, "A...
A metric owner is a process owner, champion and advocate responsible...
The implementation of appropriate technical and organizational...
DLP network, storage, scans and privacy tools can be used to identify...
A U.S. professional organization of certified public accountants and...
The process in which individually identifiable data is altered in such...
_____ takes specific identifying values and makes them broader, such...
_____ addition takes identifying values from a given data set and...
_____ is the most basic version of anonymization and it simply removes...
Anonymization is the process in which individually identifiable data...
A set of non-binding principles adopted by the Asia-Pacific Economic...
The first of four phases of the privacy operational life cycle _____
Privacy Operational Life Cycle Focused on refining and improving...
High-level, five-phase audit approach. The steps include: Audit...
Audit Life Cycle is a high-level, five-phase audit approach. The steps...
_____ is targeted at individuals based on the observation of their...
_____ are appropriate safeguards allowed by the General Data...
The United States' Federal Trade Commission's _____ (BoC) enforces the...
The United States' Federal Trade Commission's _____ (BoCP) stops...
The United States' Federal Trade Commission's _____ (BoE) helps the...
The starting point for assessing the needs of the privacy...
BCDR or _____ is a risk mitigation plan designed to prepare an...
The _____ (BCP) is typically drafted and maintained by key...
_____ (COPPA) is a U.S. federal law that applies to the operators of...
In the context of consent, _____ refers to the idea that consent must...
Three common information security principles from the 1960s. _____
The three common information security principles from the 1960s that...
A fair information practices principle, it is the principle stating...
This privacy requirement is one of the fair information practices....
A requirement that an individual "signifies" his or her...
Implied consent arises where consent may reasonably be inferred from...
Any person or entity that complies or evaluates personal information...
"As-is" data privacy requirements; the current environment and any...
Relatively new form of insurance protection that fills gaps typically...
The unauthorized acquisition of computerized data that compromises the...
The natural or legal person, public authority, agency or any other...
Also known as a record of authority, identifies personal data as it...
Also known as Information Life Cycle Management (ILM) or data...
The idea that one should only collect and retain that personal data...
Independent public authorities that supervise the application of data...
Required by the General Data Protection Regulation in some instances,...
A fair information practices principle, it is the principle that...
Also known as "local governance," this governance model involves the...
When the seller directly contacts an individual. _____
Proposed regulatory policy, similar to the existing Do-Not-Call...
This law updated the Federal Wiretap Act of 1968. As amended, it...
This Directive was replaced by the General Data Protection...
Performed to determine the capability of current privacy management to...
_____ (GAPP) is a framework promulgated by the American Institute of...
_____ or GLBA is the commonly used name for The Financial Services...
A U.S. law passed to create national standards for electronic...
This privacy governance model allows for a combination of centralized...
It is fair information practices principle that an individual should...
_____ recognizes that data has different value, and requires...
Also known as (DLM) or data governance, ILM is a policy-based approach...
Practices that provide management, technical and operational controls...
Also known as "the C-I-A triad"; consists of three common information...
Professionals and departments within an organization who have...
The authority of a court to hear a particular case. _____
Also known as "decentralized governance," this governance model...
The processes and methods to sustain a metric to match the...
The processes and methods to sustain a metric to match the...
Tools that facilitate decision-making and accountability through...
_____ or NIST is an agency within the Department of Commerce. NIST has...
An organization will be liable for damages if it breaches a legal duty...
NPI is defined by GLBA as: (i) provided by a consumer to a financial...
A fair information practices principle. There should be a general...
One of two central concepts of choice. It means an individual makes an...
One of two central concepts of choice. It means an individual's lack...
_____ (OECD) An international organization that promotes policies...
A self-regulatory system that provides an enforceable security...
The process of formulating or selecting metrics to evaluate...
Defined broadly in the General Data Protection Regulation as any...
A synonym for "personal data." It is a term with particular...
_____ (PIPEDA) A Canadian act with two goals: (1) to instill trust in...
_____ (P3P) A machine-readable language that helps to express a...
_____ as a specific term was first outlined in a framework in the...
An executive who serves as the privacy program sponsor and acts as an...
"An analysis of how information is handled: (i) to ensure handling...
Provides a standardized reference for companies to use in assessing...
Focused on refining and improving privacy processes, this model...
An implementation roadmap that provides the structure or checklists...
One tool used to determine whether a PIA should be conducted. _____
Privacy technology standards developed solely to be used for the...
Unless otherwise restricted by law, any individual that is harmed by a...
_____ The second of four phases of the privacy operational life cycle.
Any individually identifiable health information transmitted or...
Data points which are not directly associated with a specific...
Requires that the parties are prohibited from using or disclosing...
The fourth of four phases of the privacy operational life cycle. _____
Within the information life cycle, the concept that organizations...
An indicator used to measure the financial gain/loss (or "value") of a...
Under Article 15 of the Data Protection Directive, individuals are...
A fair information practices principle, it is the principle that...
A general term for how attackers can try to persuade a user to provide...
Individual executives within an organization who lead and "own" the...
The first high-level task necessary to implementing proactive privacy...
The first high-level task in Strategic Management necessary to...
Most legislation recognizes that data breach notifications involving...
The third of four phases of the privacy operational life cycle. It...
Commercial conduct that intentionally causes substantial injury,...
A partnership between the Department of Homeland Security and the...
Fourteen generic information security practice competency areas,...
Assessment of a third-party vendor for the vendor's privacy and...
Recordings that do not have sound. _____
Created by the American Institute of Certified Public Accountants...
• Identify privacy obligations
...
Include:
...
Why does an organization need a privacy program? Identify the number 1...
Why does an organization need a privacy program? Identify the number 2...
What is the most important aspect of privacy program management?
True or false? Regulatory compliance is often the primary motivation...
A privacy program should integrate privacy requirements and...
Customer service employees for a health insurance company are granted...
The most senior officer responsible for privacy in an organization,...
A statement of an organization concisely communicates its privacy...
Privacy Vision or Mission Statement of an organization concisely...
Elements of a privacy vision and mission:
Privacy Strategy Business Alignment Elements
These elements include:
...
Business alignment includes the following elements:
Data governance of personal information includes the following...
Inquiry/complaint-handling procedures includes the following elements:
Which best describes the advantages of a centralized privacy...
Which best describes the advantages of a local privacy governance...
Which best describes the advantages of a hybrid privacy governance...
Which best describes the disadvantages of a hybrid privacy governance...
Which best describes the disadvantages of a local privacy governance...
Which of the below are Tasks that the DPO is responsible for...
Match the category and skills that a DPO should possess
Match the following DPO responsibilities and categories
True or false. The DPO needs to be located in Europe?
GRC, is an umbrella term whose scope touches the privacy office, as...
Within an organization, the privacy function should always reside...
The chief privacy officer for a telecommunications company wants to...
Before determining an organization's privacy strategy, what should a...
In differentiating between a privacy strategy and a privacy framework,...
A law or regulation may constitute a privacy framework. true or false?
Match the order of the steps in developing a Privacy Program
What type of privacy governance model is defined by a one team or...
The privacy team should always comprise more than one person. true or...
Which business function ensures business and regulatory requirements...
Before the acquisition can take place the following should take place:
What are the similarities between Canada's PIPEDA and the European...
What are the differences between Canada's PIPEDA and the European...
Understanding the regulatory environment. Because the regulatory...
GDPR: Rights and obligations. How familiar are you with the rights and...
CCPA: Rights and obligations. How familiar are you with the rights and...
The California Privacy Rights Act (CPRA) ballot initiative was passed....
_____ means that one country (or jurisdiction, such as the EU) has...
_____ (language written into a contract) may be a way for...
Under the GDPR, _____ resemble the self-regulatory programs used...
_____ may also be used for GDPR compliance, although they must receive...
Under the GDPR, BCRs require approval from a supervisory authority. At...
Which are common elements of privacy-related legislation across...
Privacy and data protection regulators/oversight agencies have the...
What can controllers and processors do to avoid incurring penalties...
Two global pharmaceutical companies have recently merged. What are...
Using a valid mechanism for transferring personal information across...
Which cross-border data transfer mechanism is used to demonstrate to...
Match the elements to either Data Inventory & Mapping or Privacy...
Match the elements with with the considerations for building a data...
Match the following events with the relevant department in an...
From the list, check the events that may trigger the need for a...
Match the following components of a DPIA in the order conducted.
In addition to identifying areas of non-compliance, assessments may...
Match the considerations with the elements involved in assessing...
Match the terms to complete the sentences about items in a vendor...
Mergers, acquisitions and divestitures serve as key junctures for...
Which of the following is a common function of a data inventory?...
Which of the following elements may be found in a data inventory?...
True or false? Data inventories are almost always created and...
Which of the following is a potential tool for keeping a data...
Which of the following is an assessment that measures how closely an...
True or false? A privacy impact assessment can help facilitate privacy...
Ideally, when should a PIA be conducted? Select all that apply.
Which of the following are methods for assessing vendors? Select all...
A privacy policy is one of the two primary types of documents that...
Information security policies: Access and data classification....
Vendors should be held to the same privacy standards as the...
Procurement: Engaging vendors Match the considerations with the...
HR handles diverse employee personal information and typically will...
Data retention and destruction policies should support the idea that...
Privacy-related policies will not be effective if individuals do not...
Implementing policies. Privacy-related policies will not be effective...
Select the ones you like
An information security team is crafting an internal document that...