Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 27 pages
Exam (elaborations)

CIPT STUDY GUIDE 2026.pdf 1. Document information

Document preview thumbnail
Preview 3 out of 27 pages

CIPT STUDY GUIDE 1. Document information

Content preview

CIPT STUDY GUIDE 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔Individual Participation Principle - ✔✔A fair information practices principle, it is the
principle that an individual should have the right to access, edit or delete data

✔✔Accountability Principle - ✔✔A fair information practices principle states that
individuals controlling the collection or use of personal information should be
accountable for taking steps to ensure the implementation of these principles (FIPPs)

✔✔NIST framework - ✔✔National Institutes of Standards & Technologies; explicitly
addresses vulnerabilities, adverse events and relative likelihoods of impacts of those
events

✔✔NICE framework - ✔✔National Initiative for Cybersecurity Education; divides
computer security work into:
- securely provision
- operate & maintain
- protect & defend
- investigate
- analyze
- oversee & govern
- collect & operate

✔✔Factors Analysis in Information Risk (FAIR) - ✔✔International standard quantitative
model for security risk;
The purpose is to find factors that can be calculated or reasonably estimated, thus
building up an estimate of the overall risk

✔✔Privacy risk - ✔✔The probable frequency and probable magnitude of future privacy
violations

✔✔Action frequency - ✔✔The probable frequency, given a time frame, that a threat
actor acts toward an individual in a way that is a potential privacy violation (attempt
frequency * vulnerability = action frequency)

✔✔Attempt frequency - ✔✔The probable frequency, given a time frame, that a threat
actor attempts an act toward an individual
(opportunity * probability of action = attempt frequency)

✔✔Vulnerability - ✔✔The probability that a threat actor's acts will succeed
(capability * difficulty = vulnerability)

,✔✔Opportunity - ✔✔The probable frequency, given a time frame, at which a threat actor
will come in contact with an individual or the individual's information & be provided the
opportunity to act in a way that could cause a privacy violation

✔✔Probability of action - ✔✔The probability that a threat actor will act in a way that is a
potential privacy violation, if given the opportunity

✔✔Capability - ✔✔The skills and resources available to a threat actor in a given
situation to act in a way that is a potential privacy violation

✔✔Difficulty - ✔✔The impediments that a threat actor in a given situation must
overcome to act in a way that is a potential privacy violation

✔✔Violation magnitude - ✔✔The probable extent to which the potential privacy violation
constitutes an actual privacy violation for the affected population and the adverse
consequential risks to that population from that privacy violation (population magnitude *
adverse consequences risk = violation magnitude)

✔✔Population magnitude - ✔✔The probable population for which a potential privacy
violation is an actual privacy violation

✔✔Adverse consequences risk - ✔✔The probable frequency & probable magnitude of
adverse consequences on the affected population
(consequences frequency * consequences magnitude = adverse consequences risk)

✔✔Consequences frequency - ✔✔The probable frequency of adverse consequence on
the affected population

✔✔Consequences magnitude - ✔✔The probable magnitude of adverse consequence
on the affected population

✔✔Proactive, not reactive (PbD) - ✔✔Privacy must be a forethought in any product,
service, system or process. Privacy considerations should help drive the design, not the
reverse (the design driving privacy violations)

✔✔Privacy as the default setting (PbD) - ✔✔Individuals should not have to resort to
self-help to protect their privacy; the default should be privacy preserving. Activities that
exceed the expected context must require affirmative informed consent of the individual

✔✔Embedded into design (PbD) - ✔✔Privacy should be so ingrained into the design
that the system or process wouldn't function without the privacy-preserving functionality

, ✔✔Full functionality (positive sum, not zero sum) (PbD) - ✔✔Privacy and other design
requirements should not be treated as a trade-off. Designers must develop creative win-
win solutions

✔✔Full lifecycle protection (end-to-end security) (PbD) - ✔✔End-to-end security; From
cradle to grave, security of personal information must be considered at every stage of
the information life cycle: collecting, processing, storage, distribution and destruction

✔✔Visibility & transparency (PbD) - ✔✔The use of personal information should not be
obscured or obfuscated, and disclosure about that use must consider the needs and
sophistication of the respective audiences

✔✔Respect for user privacy (PbD) - ✔✔The individual is the principal beneficiary of
privacy and the one affected when that privacy is violated; therefore, their needs and
risks should be forefront in the minds of designers

✔✔Privacy by Design principles - ✔✔1. Proactive, not reactive
2. Privacy as the default setting
3. Privacy embedded into design
4. Positive sum, not zero sum (full functionality)
5. End-to-end security (full lifecycle protection)
6. Visibility & transparency
7. Respect for user privacy

✔✔Value sensitive design - ✔✔Value-sensitive design is a design approach that
accounts for ethical values, such as privacy, in addition to usability-oriented design
goals. Value-sensitive design places people, their needs and values important to them
at the center of the design process

✔✔How design affects users - ✔✔Transparency & user rights are core concepts of
global privacy legislation & guidelines, and customers should be able to make informed
privacy & consent decisions

✔✔Strategies for skillful practice - ✔✔TBD

✔✔Data lifecycle - ✔✔1. Collection
2. Use
3. Disclosure
4. Retention
5. Destruction

✔✔Collection - ✔✔Only collect data for established purposes and always collect
consent from data subjects for sensitive data; allow data subjects to opt out of services
they deem unnecessary and before collecting the data, when possible

Document information

Uploaded on
July 19, 2026
Number of pages
27
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALK
3.5
(40)
Sold
278
Followers
8
Items
32861
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions