✔✔This is a specific subset of information is extrapolated from the larger data set,
which leads to invalid/incorrect conclusions. - ✔✔Selective Use
✔✔Many times the mean is used for a metric, but it is sometimes more appropriate to
use the median or mode rather than the true mean/average - ✔✔Well-chosen Average
✔✔When an individual is unable to provide their point, this may result with the exclusion
of elements of a measurement when conveying results - ✔✔Semi-attachment
✔✔This measurement completely excludes certain elements from the data population,
thus providing on a partial set of data and leading to false assumptions - ✔✔Biased
Sample
✔✔An ethical issue, this occurs when data is knowingly and purposely omitted that may
have a detrimental effect on the metric or metric owner - ✔✔Intentional Deciet
✔✔This is slightly adjusting measurements to provide the appearance of success or
other-than-actual results, leading the reviewer to believe the metric is more successful
than it actually may be - ✔✔Massaging the Numbers
✔✔This occurs when inferences are made concerning a general data population that
leads to poor conclusions - ✔✔Over-generalizations
✔✔As a basic business practice in the selection of metrics, the privacy professional
should select how many key privacy metrics that focus on the key organizational
objectives - ✔✔Three to five
✔✔This is a data pattern that shows trends in an upwards or downward tendency i.e,
privacy breaches over time - ✔✔Time series
, ✔✔This is an indicator used to measure the financial gain/loss (or value) of a project in
relation to its cost - ✔✔Return on Investment (ROI)
✔✔Return on Investment (ROI) is measured how - ✔✔(Benefits - Costs) / Costs
✔✔Privacy ROI defines metrics to measure the effectiveness of investments to protect
investments in what? - ✔✔Physical assets, Personnel assets, IT assets, Operational
assets
✔✔This term relates to the protection of hardware, software, and data against physical
threats, to reduce or prevent disruptions to operations and services and loss of assets -
✔✔Physical assets
✔✔These are measures to reduce the likelihood and severity of accidental and
intentional alteration, destruction, misappropriation, misuse, misconfiguration,
unauthorized distribution and unavailability of an organization's logical and physical
assets, as the result of action or inaction by insiders and known outsiders, like business
partners - ✔✔Personnel assets
✔✔Inherent technical features that collectively protect the organizational infrastructure,
achieving and sustaining confidentiality, integrity, availability, and accountability. - ✔✔IT
assets
✔✔As it relates to ROI metrics, the first step is to identify and characterize the ROI
metric to address what? - ✔✔The specific risk that control or feature is supposed to
mitigate
✔✔As it relates to ROI metrics, the second step is to define what - ✔✔the value of the
asset
✔✔This is the ability to rapidly adapt and respond to business disruptions and to
maintain continuous business operations - ✔✔Business Resiliency
✔✔The privacy professional or organization should include in the privacy budget the
costs to generate what? - ✔✔metrics
✔✔The most time consuming task of a privacy professional was of a strategic nature,
which was what? - ✔✔advising the organization on privacy issues
✔✔What are the phases of the privacy operational life cycle - ✔✔o Assess (measure)
o Protect (improve)
o Sustain (evaluate)
o Respond (support)