Data Management and Privacy Controls Flashcards
6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Management and Privacy Controls flashcards as text
Which data classification level TYPICALLY requires the most stringent access controls and encryption?
Answer: Confidential/Restricted
Confidential or restricted data carries the highest sensitivity, requiring strict access controls, encryption, and audit logging.
A data retention policy should PRIMARILY be based on:
Answer: Legal, regulatory, and business requirements for each data type
Retention periods must align with applicable laws, regulations, and contractual obligations specific to each data category.
The principle of data minimization requires organizations to:
Answer: Collect and retain only the personal data necessary for a specific purpose
Data minimization limits collection to only what is needed, reducing privacy risk and regulatory exposure.
Which of the following BEST describes data sovereignty?
Answer: The legal principle that data is subject to the laws of the country in which it is stored
Data sovereignty means that data stored in a particular country is governed by that country's laws and regulations.
A database activity monitoring (DAM) tool PRIMARILY helps an IS auditor by:
Answer: Providing real-time visibility into who is accessing and modifying database data
DAM tools capture and analyze all database activity, enabling detection of unauthorized access, privilege abuse, and policy violations.
When personally identifiable information (PII) must be used in a test environment, the BEST practice is to:
Answer: Use data masking or anonymization to de-identify the PII
Data masking replaces real PII with realistic but fictitious values, eliminating privacy risk while preserving data format for testing.