SURE A+
✔✔Information Life Cycle Management - ✔✔Also known as data life cycle management
(DLM) or data governance, ILM is a policy-based approach to managing the flow of
information through a life cycle from creation to final disposition. ILM provides a holistic
approach to the processes, roles, controls and measures necessary to organize and
maintain data, and has 11 elements: Enterprise objectives; minimalism; simplicity of
procedure and effective training; adequacy of infrastructure; information security;
authenticity and accuracy of one's own records; retrievability; distribution controls;
auditability; consistency of policies; and enforcement.
Reference(s) in IAPP Certification Textbooks: M105-110, 142
✔✔Information Security Practices - ✔✔Provide management, technical and operational
controls to reduce probable damage, loss, modification or unauthorized data access.
✔✔Information Security Triad - ✔✔Also known as "the C-I-A triad"; consists of three
common information security principles: Confidentiality, integrity, and availability.
✔✔Internal Partners - ✔✔Professionals and departments within an organization who
have ownership of privacy activities, e.g., human resources, marketing, information
technology.
✔✔Local Governance - ✔✔Also known as "decentralized governance," this governance
model involves the delegation of decision-making authority down to the lower levels in
an organization, away from and lower than a central authority. There are fewer tiers in
the organizational structure, wider span of control and bottom-to-top flow of decision-
making and ideas.
✔✔Metric Life Cycle - ✔✔The processes and methods to sustain a metric to match the
ever-changing needs of an organization. Consists of a 5-step process: (1) Identification
of the intended audience; (2) Definition of data sources; (3) Selection of privacy metrics;
, (4) Collection and refinement of systems/application collection points; and (5) Analysis
of the data/metrics to provide value to the organization and provide a feedback quality
mechanism.
✔✔Metrics - ✔✔Tools that facilitate decision-making and accountability through
collection, analysis, and reporting of data. They must be measurable, meaningful,
clearly defined (with boundaries), indicate progress, and answer a specific question to
be valuable and practical.
✔✔Non-Public Personal Information - ✔✔Is defined by GLBA as personally identifiable
financial information (i) provided by a consumer to a financial institution, (ii) resulting
from a transaction or service performed for the consumer, or (iii) otherwise obtained by
the financial institution. Excluded from the definition are (i) publicly available information
and (ii) any consumer list that is derived without using personally identifiable financial
information.
✔✔Openness - ✔✔A fair information practices principle, it is the principle that there
should be a general policy of openness about developments, practices and policies with
respect to personal data. Means should be readily available to establish the existence
and nature of personal data, and the main purposes of their use, as well as the identity
and usual residence of the data controller.
✔✔Organization for Economic Cooperation and Development - ✔✔An international
organization that promotes policies designed to achieve the highest sustainable
economic growth, employment and a rising standard of living in both member and non-
member countries, while contributing to the world economy.
✔✔PCI Data Security Standard - ✔✔A self-regulatory system that provides an
enforceable security standard for payment card data. The rules were drafted by the
Payment Card Industry Security Standards Council, which built on previous rules written
by the various credit card companies. Except for small companies, compliance with the
standard requires hiring a third party to conduct security assessments and detect
violations. Failure to comply can lead to exclusion from Visa, MasterCard or other major
payment card systems, as well as penalties.
✔✔Performance Measurement - ✔✔The process of formulating or selecting metrics to
evaluate implementation, efficiency or effectiveness; gathering data and producing
quantifiable output that describes performance.
✔✔Personal Information - ✔✔May refer to either a generic term for information, or an
EU term for such information. In the U.S., such information may be referred to as
Personally Identifiable Information
✔✔Personal Information Protection and Electronic Documents Act - ✔✔A Canadian act
with two goals: (1) to instill trust in electronic commerce and private sector transactions