โ† All CDPSE Flashcard Decks

Governance Frameworks Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Governance Frameworks flashcards as text
  1. A global e-commerce company has a well-established ISO/IEC 27001 certified Information Security Management System (ISMS). To better align with global privacy regulations like GDPR and CCPA, the company decides to implement ISO/IEC 27701. How does ISO/IEC 27701 relate to their existing ISMS?

    Answer: It serves as a privacy-specific extension, enhancing the ISMS to become a Privacy Information Management System (PIMS).

    ISO/IEC 27701 is designed as an extension to an existing ISO/IEC 27001 ISMS. It adds privacy-specific requirements and controls, effectively upgrading the ISMS into a PIMS (Privacy Information Management System). It does not replace the ISMS but builds upon its foundation.

  2. A software development team is creating a new mobile application that will collect user location data. To adhere to the principle of 'Privacy by Default', which of the following design choices should be implemented?

    Answer: Disabling geolocation services by default and requiring the user to actively turn them on for specific features.

    Privacy by Default, a key concept in Privacy by Design, mandates that the most privacy-protective settings are applied automatically without any user action. Therefore, features like geolocation should be turned off by default, and users should have to make a conscious, affirmative choice (opt-in) to enable them.

  3. According to the NIST Privacy Framework, which of the following is NOT one of the five core Functions?

    Answer: Remediate

    The five core Functions of the NIST Privacy Framework are Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P. 'Remediate' is a common term in security frameworks related to incident response but is not one of the high-level Functions in this specific privacy framework.

  4. A financial institution is launching a new AI-driven service to analyze customer spending habits and offer personalized loan products. This involves processing large volumes of sensitive financial data and making automated decisions. Within a robust privacy governance framework, what is the MOST critical activity to perform before launching this service?

    Answer: Conducting a Data Protection Impact Assessment (DPIA).

    Given that the new service involves processing sensitive data on a large scale and uses new technology (AI) for profiling and automated decision-making, it is considered a high-risk processing activity. Under regulations like GDPR, conducting a Data Protection Impact Assessment (DPIA) is mandatory for such high-risk projects to identify and mitigate privacy risks before they materialize.

  5. Which of the following best describes the primary role of a Data Protection Officer (DPO) within a privacy governance framework?

    Answer: To independently advise on and monitor compliance with data protection laws.

    The Data Protection Officer (DPO) is a senior, independent role responsible for advising the organization on its data protection obligations, monitoring internal compliance, conducting DPIAs, and acting as a contact point for supervisory authorities and data subjects. Their key function is oversight and advisory, not direct implementation of all controls or other business functions.

  6. A key principle within the GDPR is 'Accountability'. What does this principle require of an organization?

    Answer: To be responsible for and able to demonstrate compliance with all GDPR principles.

    The accountability principle, as defined in Article 5(2) of the GDPR, requires that data controllers are not only responsible for complying with the GDPR's principles but must also be able to demonstrate that compliance. This involves maintaining documentation, implementing data protection by design and default, and having appropriate policies and procedures in place.