A System of Records Notice (SORN) is not required if an organization determines that PII
will be stored using a system if records correct answers true
An organization with an existing system of records decides to start using PII for a new
purpose outside the "routine use" defined in the System of Records Notice (SORN). Is this a
permitted use? correct answers no
What law establishes the federal government's legal responsibility for safeguarding PII?
correct answers The Freedom of Information Act (FOIA)
Information that can be combined with other information to link solely to an individual is
considered PII correct answers true
An organization that fails to protect PII can face consequences including: correct answers all
of the above
Which of the following are examples of PII? correct answers - Social Security Number (SSN)
- Driver's License Number
- Fingerprint
1) This regulation governs the DoD Privacy Program
2) This law establishes the public's rigth to access federal government information
3) Thai guidance identifies federal information security controls
4) This law establishes the federal government's legal responsibility for safeguarding PII
correct answers 1) 5400.11-R: DoD Privacy Program
2) FOIA
3) OMB M-17-12
4) Privacy Act of 1974
The individual to whom the record pertains has submitted a written request for the
information in question correct answers this use/disclosure is authorized
Your organization seeks no use to record for routine use, as defined in the SORN correct
answers authorize
Your organization is using existing records for the new purpose and has not yet published a
SORN correct answers not authorized
Which of the following is responsible for most of the recent PII data breaches? correct
answers phishing
Which of the following is not an example of an administrative safeguard that organizations
use to protect PII? correct answers SORN
Which of the following is NOT included in a breach notification? correct answers Articles
and other media reporting the breach