CIPM IAPP EXAM QUESTIONS AND
CORRECT ANSWERS
The Respond phase of the privacy operational life cycle includes which principles? -
Answer-Information requests, legal compliance, incident response planning and incident
handling
The form of Redress that is offered to the complainant should be clearly defined in
what? - Answer-Your complaint response process and documented for resolution
Data integrity issues are often the results of what? - Answer-Human failure or systemic
error.
The fundamental principle that should govern a privacy incident is to what? - Answer-
Allow an affected person the opportunity to protect themselves from identify theft or
other harm
The primary focus when managing any privacy incident is always what? - Answer-Harm
prevention and/or minimization
It is best practice to have the notice of a breach issued to the affected individuals by
whom? - Answer-The organization that these individuals are likely to recognize from a
prior or current relationship
The privacy statement should indicate: - Answer-(1) The value the organization places
on privacy\n\n\n(2) Desired organizational objectives\n\n\n(3) Strategies to drive the
tactics used to achieve the intended outcomes\n\n\n(4) Clarification of roles and
responsibilities
Privacy Worshop - Answer-Conduct a privacy workshop for your stakeholders to level
the privacy playing field by defining privacy for the organization, explaining the market
expectations, answering questions, and reducing confusion.
What enables you to create a data-governance strategy for your organization? -
Answer-Taking an inventory of relevant regulations that apply to your business.
Rationalizing requirements (as part of creating a data governance strategy) means... -
Answer-Taking a more pragmatic approach and collect the various data protection
requirements and "rationalize" them where you can. Rationalizing means implementing
a solution that materially addresses the various requirements of the majority of laws and
,regulations which you must comply. * must address high risk exceptions as part of this
process too!
Strictest Standard (another data governance strategy for personal information) -
Answer-Look to the strictest standard when seeking a solution; provided it does not
violate any (1) data privacy laws (2) exceed budgetary restrictions (3) contradict
organization goals and objectives.
First step of developing a Privacy Policy Framework? - Answer-Assessment of the
Business Case for the current (or forthcoming) privacy program or privacy requirements
for privacy policies, standards, and/or guidelines.
Second step of developing a Privacy Policy Framework? - Answer-A gap analysis of the
information collected for the Business Case, ensuring there are no gaps or holes in the
current or developing privacy program.
Third and final step of developing a Privacy Policy Framework? - Answer-Review and
Monitor the program and Communicate the Privacy Policy Framework.
No matter the size of an organization, if the core business of the organization revolves
around the processing of personal data... - Answer-...having in place as thorough a
Privacy Policy Framework as possible becomes all the more important and should be
prioritized within the organization.
Strategic Management is the first high level necessary task to implement proactive
privacy management through the following 3 subtasks: - Answer-(1) Define Privacy
Vision and Privacy Mission Statement\n\n(2) Develop Privacy Strategy\n\n(3) Structure
Privacy Team
Strategic management of privacy starts by creating or updating the organization vision
and mission statement based on privacy best practices that should include: - Answer-(1)
Develop vision and mission statement objectives\n\n(2) Define privacy program
scope\n\n\n(3) Identify legal and regulatory compliance challenges\n\n\n(4) Identify
organization personal information legal requirements
Define Privacy Program Scope - Answer-1) Identify & Understand Legal and Regulatory
Compliance Challenges\nii) Identify the Data Impacted\n\n*Understand Global
Perspective\n*Customize Approach\n*Be Aware of Laws, Regulations, Processes,
Procedures\n*Monitor Legal Compliance Factors
Types of Protection Models (4) - Answer-i) Sectoral (US)\nii) Comprehensize (EU,
Canada, Russia)\niii) Co-Regulatory (Australia)\niv) Self Regulated (US, Japan,
Singapore)
Questions to Ask When Determining Privacy Requirements (Legal) - Answer-- Who
collects, uses, maintians Personal Information\n- What are the types of Personal
, Information\n- What are the legal requirements for the PI\n- Where is the PI stored\n-
How is the PI collected\n- Why is the PI collected
Steps to Developing a Privacy Strategy (5) - Answer-i) ID Stakeholders and Internal
Partnerships\nii) Leverage Key Functions\niii) Create a Process for Interfacing\niv)
Develop a Data Governance Strategy\nv) *Conduct a Privacy Workshop
Data Governance Models (3) - Answer-i) Centralized\nii) Local/Decentralized\niii) Hybrid
What is a Privacy Program Framework? - Answer-Implementation roadmap that
provides structure or checklists to guide privacy professionals through management and
prompts for details to determine privacy relevant decisions.
Popular Frameworks (6) - Answer-APEC Privacy - regional data transfers\nPIPEDA
(Canada) & AIPP (Australian)\nOCED\nPrivacy by Design\nUS Government
Steps to Develop Privacy Policies, Standards, Guidelines (4) - Answer-i) Assessment of
Business Case \nii) Gap Analysis - \niii) Review & Monitor\niv) Communicate
Business Case - Answer-Defines individual program needs and way to meet specific
goals.\n\n- Org Privacy Guidance\n- Define Privacy\n- Laws/Regs\n- Technical
Controls\n- External Privacy Orgs\n- Frameworks\n- Privacy Enhancing Tech (PETs)\n-
Education/Awareness\n- Program Assurance
What are the 4 Parts of the Privacy Operational Life Cycle - Answer-i) Assess\nii)
Protect\niii) Sustain\niv) Respond
5 Maturity Levels of the AICPA/CICA Privacy Maturity Model? - Answer-i) Ad Hoc -
Procedures informal, incomplete, inconsistently applied (not written)\nii) Repeatable -
Procedures exist, partially documented, don't cover all areas\niii) Defined - All
documented, implemented, cover all relevant aspects\niv) Managed - Reviews
conducted assess effectiveness of controls\nv) Optimized - Regular reviews and
feedback to ensure continuous improvements.
Privacy Assessment Approach (Key Areas) - Answer-i) Internal Audit & Risk
Management\nii) Information Tech & IT Operations/Development\niii) Information
Security\niv) HR/Ethics\nv) Legal/Contracts\nvi) Process/3rd Party Vendors\nvii)
Marketing/Sales\nviii) Government Relations\nix) Accounting/Finance
11 Principles of the Data Life Cycle Management Model - Answer-i) Enterprise
Objectives\nii) Minimalism\niii) Simplicity of Procedures & Training\niv) Adequacy of
Infrastructure\nv) Information Security\nvi) Authenticity and Accuracy of Records\nvii)
Retrievabiliyt\nviii) Distribution Controls\nix) Auditability\nx) Consistency of Policies\nxi)
Enforcement
CORRECT ANSWERS
The Respond phase of the privacy operational life cycle includes which principles? -
Answer-Information requests, legal compliance, incident response planning and incident
handling
The form of Redress that is offered to the complainant should be clearly defined in
what? - Answer-Your complaint response process and documented for resolution
Data integrity issues are often the results of what? - Answer-Human failure or systemic
error.
The fundamental principle that should govern a privacy incident is to what? - Answer-
Allow an affected person the opportunity to protect themselves from identify theft or
other harm
The primary focus when managing any privacy incident is always what? - Answer-Harm
prevention and/or minimization
It is best practice to have the notice of a breach issued to the affected individuals by
whom? - Answer-The organization that these individuals are likely to recognize from a
prior or current relationship
The privacy statement should indicate: - Answer-(1) The value the organization places
on privacy\n\n\n(2) Desired organizational objectives\n\n\n(3) Strategies to drive the
tactics used to achieve the intended outcomes\n\n\n(4) Clarification of roles and
responsibilities
Privacy Worshop - Answer-Conduct a privacy workshop for your stakeholders to level
the privacy playing field by defining privacy for the organization, explaining the market
expectations, answering questions, and reducing confusion.
What enables you to create a data-governance strategy for your organization? -
Answer-Taking an inventory of relevant regulations that apply to your business.
Rationalizing requirements (as part of creating a data governance strategy) means... -
Answer-Taking a more pragmatic approach and collect the various data protection
requirements and "rationalize" them where you can. Rationalizing means implementing
a solution that materially addresses the various requirements of the majority of laws and
,regulations which you must comply. * must address high risk exceptions as part of this
process too!
Strictest Standard (another data governance strategy for personal information) -
Answer-Look to the strictest standard when seeking a solution; provided it does not
violate any (1) data privacy laws (2) exceed budgetary restrictions (3) contradict
organization goals and objectives.
First step of developing a Privacy Policy Framework? - Answer-Assessment of the
Business Case for the current (or forthcoming) privacy program or privacy requirements
for privacy policies, standards, and/or guidelines.
Second step of developing a Privacy Policy Framework? - Answer-A gap analysis of the
information collected for the Business Case, ensuring there are no gaps or holes in the
current or developing privacy program.
Third and final step of developing a Privacy Policy Framework? - Answer-Review and
Monitor the program and Communicate the Privacy Policy Framework.
No matter the size of an organization, if the core business of the organization revolves
around the processing of personal data... - Answer-...having in place as thorough a
Privacy Policy Framework as possible becomes all the more important and should be
prioritized within the organization.
Strategic Management is the first high level necessary task to implement proactive
privacy management through the following 3 subtasks: - Answer-(1) Define Privacy
Vision and Privacy Mission Statement\n\n(2) Develop Privacy Strategy\n\n(3) Structure
Privacy Team
Strategic management of privacy starts by creating or updating the organization vision
and mission statement based on privacy best practices that should include: - Answer-(1)
Develop vision and mission statement objectives\n\n(2) Define privacy program
scope\n\n\n(3) Identify legal and regulatory compliance challenges\n\n\n(4) Identify
organization personal information legal requirements
Define Privacy Program Scope - Answer-1) Identify & Understand Legal and Regulatory
Compliance Challenges\nii) Identify the Data Impacted\n\n*Understand Global
Perspective\n*Customize Approach\n*Be Aware of Laws, Regulations, Processes,
Procedures\n*Monitor Legal Compliance Factors
Types of Protection Models (4) - Answer-i) Sectoral (US)\nii) Comprehensize (EU,
Canada, Russia)\niii) Co-Regulatory (Australia)\niv) Self Regulated (US, Japan,
Singapore)
Questions to Ask When Determining Privacy Requirements (Legal) - Answer-- Who
collects, uses, maintians Personal Information\n- What are the types of Personal
, Information\n- What are the legal requirements for the PI\n- Where is the PI stored\n-
How is the PI collected\n- Why is the PI collected
Steps to Developing a Privacy Strategy (5) - Answer-i) ID Stakeholders and Internal
Partnerships\nii) Leverage Key Functions\niii) Create a Process for Interfacing\niv)
Develop a Data Governance Strategy\nv) *Conduct a Privacy Workshop
Data Governance Models (3) - Answer-i) Centralized\nii) Local/Decentralized\niii) Hybrid
What is a Privacy Program Framework? - Answer-Implementation roadmap that
provides structure or checklists to guide privacy professionals through management and
prompts for details to determine privacy relevant decisions.
Popular Frameworks (6) - Answer-APEC Privacy - regional data transfers\nPIPEDA
(Canada) & AIPP (Australian)\nOCED\nPrivacy by Design\nUS Government
Steps to Develop Privacy Policies, Standards, Guidelines (4) - Answer-i) Assessment of
Business Case \nii) Gap Analysis - \niii) Review & Monitor\niv) Communicate
Business Case - Answer-Defines individual program needs and way to meet specific
goals.\n\n- Org Privacy Guidance\n- Define Privacy\n- Laws/Regs\n- Technical
Controls\n- External Privacy Orgs\n- Frameworks\n- Privacy Enhancing Tech (PETs)\n-
Education/Awareness\n- Program Assurance
What are the 4 Parts of the Privacy Operational Life Cycle - Answer-i) Assess\nii)
Protect\niii) Sustain\niv) Respond
5 Maturity Levels of the AICPA/CICA Privacy Maturity Model? - Answer-i) Ad Hoc -
Procedures informal, incomplete, inconsistently applied (not written)\nii) Repeatable -
Procedures exist, partially documented, don't cover all areas\niii) Defined - All
documented, implemented, cover all relevant aspects\niv) Managed - Reviews
conducted assess effectiveness of controls\nv) Optimized - Regular reviews and
feedback to ensure continuous improvements.
Privacy Assessment Approach (Key Areas) - Answer-i) Internal Audit & Risk
Management\nii) Information Tech & IT Operations/Development\niii) Information
Security\niv) HR/Ethics\nv) Legal/Contracts\nvi) Process/3rd Party Vendors\nvii)
Marketing/Sales\nviii) Government Relations\nix) Accounting/Finance
11 Principles of the Data Life Cycle Management Model - Answer-i) Enterprise
Objectives\nii) Minimalism\niii) Simplicity of Procedures & Training\niv) Adequacy of
Infrastructure\nv) Information Security\nvi) Authenticity and Accuracy of Records\nvii)
Retrievabiliyt\nviii) Distribution Controls\nix) Auditability\nx) Consistency of Policies\nxi)
Enforcement