ANSWERS SURE A+
✔✔Data-protection regulations typically include what items - ✔✔• Notice
• Choice
• Consent
• Purpose limitations
• Limits on retaining data
• Individual rights to access
• Correction and deletion of data
• Obligation to safeguard data
✔✔Privacy professionals should always involve whom to review, define or establish
technical security controls, including common security controls such as firewalls,
malware anti-virus, and complex password requirements - ✔✔Security Engineer
✔✔This strategy seeks solutions that do not violate any data privacy laws, exceed
budgetary restrictions or contradict organization goals and objectives - ✔✔Strictest
Standard
✔✔When positioning the privacy team, you should also consider the authority it will
receive based on the what? - ✔✔Governance model it follows
✔✔Executive leadership support for your governance model will have a direct impact on
the level of success when implementing your privacy strategies. What are the important
steps to integrate into any model? - ✔✔o Involve senior leadership
o Involve stakeholders
o Develop internal partnerships
o Provide flexibility
o Leverage communications
o Leverage collaboration
, ✔✔This type of governance fits well in organizations used to utilize single-channel
functions (where direction flows from a single source) with planning and decision
making completed by one group - ✔✔Centralized Governance
✔✔This type of governance delegates decision-making authority down to the lower
levels in an organization; relatively away from and lower than a central authority -
✔✔Local or Decentralized
✔✔This is an implementation road map that provides the structure or checklists
(document privacy procedures and processes) to guide the privacy professional through
privacy management and prompts them for the details to determine all privacy-relevant
decisions for the organization - ✔✔Privacy Program Framework
✔✔Privacy governance framework provides the methods to what? - ✔✔Access, protect,
sustain and respond to the positive and negative effects of all influencing factors
✔✔This process provides the means to evaluate business rhythms, technical systems
and associated costs to the strategic business objectives and performance of the
organization. - ✔✔Performance Measurement with Metrics Selection
✔✔This provides quantifiable output that is measurable, meaningful, answers specific
questions and is clearly defined - ✔✔Metrics performance
✔✔Major drivers impacting the increased need for privacy metrics include what? -
✔✔Means of providing meaningful information on your privacy regime to key
stakeholders, Generational change in the use of technology, Rapid advancements to
technology, Catastrophes, such as data loss events, that drive tighter regulations, laws
and standards, Current security and privacy solutions that are not designed to deal with
the fast pace of emerging technologies or requirements, Privacy regulations becoming
more stringent while privacy exceptions rise, Professionals embrace security and
privacy as part of their job
✔✔Privacy Objectives are typically broad-based. What is an example of a privacy
objective? - ✔✔Privacy Notice
✔✔Privacy goals are specific and measurable. What is an example of a Privacy Goal? -
✔✔Provide privacy notices to 100 percent of the customer base; number of privacy
notices.
✔✔These provides common language between business, operational and technical
managers to discuss the relevant information (e.g., good, bad, or indifferent) related to
assessing progress. - ✔✔Metrics