Answers / Sure A+
11 element DLM model - (1) Enterprise Objectives\n(2) Minimalism\n(3) Simplicity of Procedure
and Effective Training\n(4) Adequacy of Infrastructure\n(5) Information Security\n(6) Authenticity and
Accuracy of One's Own Records\n(7) Retreivability\n(8) Distribution Controls\n(9) Auditability \n(10)
Consistency of Policies\n(11) Enforcement
11 Principles of the Data Life Cycle Management Model - i) Enterprise Objectives\nii)
Minimalism\niii) Simplicity of Procedures & Training\niv) Adequacy of Infrastructure\nv) Information
Security\nvi) Authenticity and Accuracy of Records\nvii) Retrievabiliyt\nviii) Distribution Controls\nix)
Auditability\nx) Consistency of Policies\nxi) Enforcement
3 keys to Sustainment? - i) Monitor\nii) Audit\niii) Communicate
4 keys to Response? - i) Information Requests\nii) Legal Compliance\niii) Incident Response
Planning\niv) Incident Handling
5 Maturity Levels of the AICPA/CICA Privacy Maturity Model? - i) Ad Hoc - Procedures informal,
incomplete, inconsistently applied (not written)\nii) Repeatable - Procedures exist, partially documented,
don't cover all areas\niii) Defined - All documented, implemented, cover all relevant aspects\niv)
Managed - Reviews conducted assess effectiveness of controls\nv) Optimized - Regular reviews and
feedback to ensure continuous improvements.
A 2012 study revealed what groups were most often the cause for privacy incidents? - Insiders
and third parties
A breach will typically involve - Third party hacker who intentionally exploits vulnerabilities of the
customer system, Customer failure to properly operate, use or secure its systems, Lost or stolen
computer equipment, Misconduct of customer employees
A metric owner must be able to do what? - Evangelize the purpose and intent of that metric to
the organization
,A metric should be clear in the meaning of what is being measured and what else? - 1) Rigorously
defined, 2) Credible and relevant, \n\n 3) Objective and quantifiable, and \n\n 4) Associated with the
baseline measurement per the organization standard metric taxonomy.
A mission statement should include what five items? - Value the organization places on privacy,
Desired organizational objectives, Strategies to drive the tactics used to achieve the intended outcomes,
Clarification of roles and responsibilities
A well known self certification framework is what? - US-EU Safe Harbor
According to Baker and McKenzie in their looking-ahead analysis of 2012, the goal of "achieving
compliance" is steadily being replaced with what? - A corporate need to "achieve and maintain
compliance"
After a breach occurs, the primary role for this stakeholder is to provide members with timely updates
and instructions. - Union Leadership
An effective metric is a clear and concise metric that defines and measures what? - Progress
toward a business objective or goal without overburdening the reader
An ethical issue, this occurs when data is knowingly and purposely omitted that may have a detrimental
effect on the metric or metric owner - Intentional Deciet
As a basic business practice in the selection of metrics, the privacy professional should select how many
key privacy metrics that focus on the key organizational objectives - Three to five
As a general practice, who should not perform the data collection tasks or perform the measurements of
the metric? - Metric Owner
As a rule, privacy policies and procedures are created and enforced at a what level? - Functional
,As it relates to ROI metrics, the first step is to identify and characterize the ROI metric to address what? -
The specific risk that control or feature is supposed to mitigate
As it relates to ROI metrics, the second step is to define what - the value of the asset
As part of the incident-response planning process, this group will provide guidance regarding the
detection, isolation, removal, and preservation of affected systems. - Information Systems (IS)
As Six Sigma teaches, an effective metric owner must do what? - 1) Know what is critical about the
metric, 2) Monitor process performance with the metric, \n\n 3) Make sure the process documentation
is up to date,\n4) Perform regular reviews, \n5) Make sure that any improvements are incorporated and
maintained in the process, \n6) Advocate the metric to customers, partners and others, and \n\n 7)
Maintain training, documentation, and materials.
Assuming privacy incident notification is required, organizations generally have how long to notify the
affected individuals - 60 days
Attributes of an effective Metric - Clear and concise metric that defines and measures progress
toward a business objective or goal without overburdening the reader
Based on these three things, the privacy professional will need to determine the best methods, style and
practices to working within the organization. - Individual culture, politics and protocols of the
organization
Because of their unique association with customers and the bond of trust built carefully over time, this
group is often asked to notify key accounts when their data has been breached - BD
Breaches - Not all breaches require notification. There are various types of notification
requirements to regulators and affected individuals. Once it is concluded that an actual compromise of
sensitive information has occurred, the pre-notification process is triggered. Steps taken may vary
depending on several factors, but the purpose is to confirm that the event does indeed constitute a
"reportable" breach.
, Business Case - Defines individual program needs and way to meet specific goals.\n\n- Org Privacy
Guidance\n- Define Privacy\n- Laws/Regs\n- Technical Controls\n- External Privacy Orgs\n-
Frameworks\n- Privacy Enhancing Tech (PETs)\n- Education/Awareness\n- Program Assurance
Business Case (as a step in developing the Privacy Policy Framework) - Allows for the
understanding of the role of privacy in the context of business requirements and identification of
business benefits and risks.
Business Resiliency Metrics - ability to rapidly adapt and respond to business disruptions
CIA Triad - Confidentiality. Prevention of unauthorized disclosure of information.\n\n\nIntegrity.
Ensures information is protected from unauthorized or unintentional alteration, modification or
deletion.\n\n\nAvailability. Information is readily accessible to authorized users.\n\n\n+2 =
Accountability, Assurance
CIA triad in additional to further advanced information security concepts are what? -
Confidentiality, Integrity, Availability, Accountability, Assurance
Combining of legal, compliance, internal audit and security functions: collaboration is assured, but what?
- functional independence is more challenging
Common reporting intervals in incident response plans include what? - Hourly, daily, weekly,
monthly
Data Governance Models (3) - i) Centralized\nii) Local/Decentralized\niii) Hybrid
Data integrity issues are often the results of what? - Human failure or systemic error.
Data Inventory - Conducting a data inventory reveals where personal data resides, which will
identify the data as it moves across various systems and thus how data is shared and organized and its
locations. That data is then categorized by subject area, which identifies inconsistent data versions,
enabling identification and mitigation of data disparities. The data inventory offers a good starting point