CIPM IAPP EXAM QUESTIONS WITH
REVIEWED 100% CORRECT
DETAILED ANSWERS GUARANTEED
PASS
When defining your privacy program scope, you must first do what? - Answer-
Understand and identify the legal and regulatory compliance challenges of the
organization and identify the data impacted
If your organization plans to do business within a jurisdiction that has inadequate or no
data protection regulations, you should do what? - Answer-Institute your organization's
requirements, policies and procedures instead of reducing them to the level of the
country
When developing your global privacy strategy, it must be relevant to what? - Answer-
Markets
Cultures
Geographical locations
According to Baker and McKenzie in their looking-ahead analysis of 2012, the goal of
"achieving compliance" is steadily being replaced with what? - Answer-A corporate
need to "achieve and maintain compliance"
What are examples of certain types of organizations and entities known as "covered
entities" - Answer-Healthcare providers (hospitals, clinics, pharmacies) and health plans
(medical plans, organization benefit plans) subject to HIPPA.
Merchants that handle cardholder information for debit, credit, prepaid, e-purse, ATM
and POS cards must be in compliance with what? - Answer-Payment Card Industry
Data Security Standard (PCI DSS), which is a global standard, not a law.
If you process personal information of any resident of a state that has adopted a breach
notification law, understand that to the extent that non-encrypted data has been
compromised, your compliance obligations may include notification to whom? - Answer-
The residents of the states, as well as government bodies or state attorney general
offices.
,What is the first step when identifying organization personal information legal
requirements - Answer-"roughing out" the scope of a privacy program by flagging areas
in an organization where personal information is likely to be collected, access or used
(HR, finance, marketing, customer relationship management systems, IT)
"Strategic Management" is the first high-level necessary task to implement proactive
privacy management through the following 3 subtasks: - Answer-(1) Define Privacy
Vision and Privacy Mission Statement
(2) Develop Privacy Strategy
(3) Structure Privacy Team
Strategic management of privacy starts by creating or updating the organization vision
and mission statement based on privacy best practices that should include: - Answer-(1)
Develop vision and mission statement objectives
(2) Define privacy program scope
(3) Identify legal and regulatory compliance challenges
(4) Identify organization personal information legal requirements
Define Privacy Program Scope - Answer-- Identify & Understand Legal and Regulatory
Compliance Challenges
- Identify the Data Impacted
- Understand Global Perspective
- Customize Approach
- Be Aware of Laws, Regulations, Processes, Procedures
- Monitor Legal Compliance Factors
Types of Protection Models (4) - Answer-i) Sectoral (US)
ii) Comprehensize (EU, Canada, Russia)
iii) Co-Regulatory (Australia)
iv) Self Regulated (US, Japan, Singapore)
Questions to Ask When Determining Privacy Requirements (Legal) - Answer-- Who
collects, uses, maintains Personal Information
,- What are the types of Personal Information
- What are the legal requirements for the PI
- Where is the PI stored
- How is the PI collected
- Why is the PI collected
Steps to Developing a Privacy Strategy (5) - Answer-i) ID Stakeholders and Internal
Partnerships
ii) Leverage Key Functions
iii) Create a Process for Interfacing
iv) Develop a Data Governance Strategy
v) Conduct a Privacy Workshop
Data Governance Models (3) - Answer-i) Centralized
ii) Local/Decentralized
iii) Hybrid
What is a Privacy Program Framework? - Answer-Implementation roadmap that
provides structure or checklists to guide privacy professionals through management and
prompts for details to determine privacy relevant decisions.
Popular Frameworks (6) - Answer-- APEC Privacy - regional data transfers
- PIPEDA (Canada) & AIPP (Australian)
- OCED
- Privacy by Design
- US Government
Steps to Develop Privacy Policies, Standards, Guidelines (4) - Answer-i) Assessment of
Business Case
ii) Gap Analysis
, iii) Review & Monitor
iv) Communicate
Business Case - Answer-Defines individual program needs and way to meet specific
goals.
- Org Privacy Guidance
- Define Privacy
- Laws/Regs
- Technical Controls
- External Privacy Orgs
- Frameworks
- Privacy Enhancing Technologies (PETs)
- Education/Awareness
- Program Assurance
What are the 4 Parts of the Privacy Operational Life Cycle - Answer-i) Assess
ii) Protect
iii) Sustain
iv) Respond
5 Maturity Levels of the AICPA/CICA Privacy Maturity Model? - Answer-i) Ad Hoc -
Procedures informal, incomplete, inconsistently applied (not written)
ii) Repeatable - Procedures exist, partially documented, don't cover all areas
iii) Defined - All documented, implemented, cover all relevant aspects
iv) Managed - Reviews conducted assess effectiveness of controls
v) Optimized - Regular reviews and feedback to ensure continuous improvements.
REVIEWED 100% CORRECT
DETAILED ANSWERS GUARANTEED
PASS
When defining your privacy program scope, you must first do what? - Answer-
Understand and identify the legal and regulatory compliance challenges of the
organization and identify the data impacted
If your organization plans to do business within a jurisdiction that has inadequate or no
data protection regulations, you should do what? - Answer-Institute your organization's
requirements, policies and procedures instead of reducing them to the level of the
country
When developing your global privacy strategy, it must be relevant to what? - Answer-
Markets
Cultures
Geographical locations
According to Baker and McKenzie in their looking-ahead analysis of 2012, the goal of
"achieving compliance" is steadily being replaced with what? - Answer-A corporate
need to "achieve and maintain compliance"
What are examples of certain types of organizations and entities known as "covered
entities" - Answer-Healthcare providers (hospitals, clinics, pharmacies) and health plans
(medical plans, organization benefit plans) subject to HIPPA.
Merchants that handle cardholder information for debit, credit, prepaid, e-purse, ATM
and POS cards must be in compliance with what? - Answer-Payment Card Industry
Data Security Standard (PCI DSS), which is a global standard, not a law.
If you process personal information of any resident of a state that has adopted a breach
notification law, understand that to the extent that non-encrypted data has been
compromised, your compliance obligations may include notification to whom? - Answer-
The residents of the states, as well as government bodies or state attorney general
offices.
,What is the first step when identifying organization personal information legal
requirements - Answer-"roughing out" the scope of a privacy program by flagging areas
in an organization where personal information is likely to be collected, access or used
(HR, finance, marketing, customer relationship management systems, IT)
"Strategic Management" is the first high-level necessary task to implement proactive
privacy management through the following 3 subtasks: - Answer-(1) Define Privacy
Vision and Privacy Mission Statement
(2) Develop Privacy Strategy
(3) Structure Privacy Team
Strategic management of privacy starts by creating or updating the organization vision
and mission statement based on privacy best practices that should include: - Answer-(1)
Develop vision and mission statement objectives
(2) Define privacy program scope
(3) Identify legal and regulatory compliance challenges
(4) Identify organization personal information legal requirements
Define Privacy Program Scope - Answer-- Identify & Understand Legal and Regulatory
Compliance Challenges
- Identify the Data Impacted
- Understand Global Perspective
- Customize Approach
- Be Aware of Laws, Regulations, Processes, Procedures
- Monitor Legal Compliance Factors
Types of Protection Models (4) - Answer-i) Sectoral (US)
ii) Comprehensize (EU, Canada, Russia)
iii) Co-Regulatory (Australia)
iv) Self Regulated (US, Japan, Singapore)
Questions to Ask When Determining Privacy Requirements (Legal) - Answer-- Who
collects, uses, maintains Personal Information
,- What are the types of Personal Information
- What are the legal requirements for the PI
- Where is the PI stored
- How is the PI collected
- Why is the PI collected
Steps to Developing a Privacy Strategy (5) - Answer-i) ID Stakeholders and Internal
Partnerships
ii) Leverage Key Functions
iii) Create a Process for Interfacing
iv) Develop a Data Governance Strategy
v) Conduct a Privacy Workshop
Data Governance Models (3) - Answer-i) Centralized
ii) Local/Decentralized
iii) Hybrid
What is a Privacy Program Framework? - Answer-Implementation roadmap that
provides structure or checklists to guide privacy professionals through management and
prompts for details to determine privacy relevant decisions.
Popular Frameworks (6) - Answer-- APEC Privacy - regional data transfers
- PIPEDA (Canada) & AIPP (Australian)
- OCED
- Privacy by Design
- US Government
Steps to Develop Privacy Policies, Standards, Guidelines (4) - Answer-i) Assessment of
Business Case
ii) Gap Analysis
, iii) Review & Monitor
iv) Communicate
Business Case - Answer-Defines individual program needs and way to meet specific
goals.
- Org Privacy Guidance
- Define Privacy
- Laws/Regs
- Technical Controls
- External Privacy Orgs
- Frameworks
- Privacy Enhancing Technologies (PETs)
- Education/Awareness
- Program Assurance
What are the 4 Parts of the Privacy Operational Life Cycle - Answer-i) Assess
ii) Protect
iii) Sustain
iv) Respond
5 Maturity Levels of the AICPA/CICA Privacy Maturity Model? - Answer-i) Ad Hoc -
Procedures informal, incomplete, inconsistently applied (not written)
ii) Repeatable - Procedures exist, partially documented, don't cover all areas
iii) Defined - All documented, implemented, cover all relevant aspects
iv) Managed - Reviews conducted assess effectiveness of controls
v) Optimized - Regular reviews and feedback to ensure continuous improvements.