← All CRM Flashcard Decks

Information Security & Privacy Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Security & Privacy flashcards as text
  1. Which security framework provides a voluntary set of guidelines for managing cybersecurity risk and is widely used by US organizations to protect information assets?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST CSF is a voluntary framework of best practices for managing and reducing cybersecurity risk, widely adopted by US public and private sector organizations.

  2. A records manager is implementing a 'clean desk policy.' What is the PRIMARY security goal of this policy?

    Answer: Prevent unauthorized access to physical records and sensitive information left unattended

    A clean desk policy requires employees to secure physical records and devices when not in use, preventing unauthorized viewing or theft.

  3. Under California's CCPA, which of the following rights is granted to California consumers regarding their personal information?

    Answer: The right to know what personal data is collected and to opt out of its sale

    The CCPA gives California consumers the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale.

  4. What is the key difference between 'anonymization' and 'pseudonymization' of records?

    Answer: Pseudonymization replaces identifiers with codes that can be re-linked; anonymization removes all identifying information permanently

    Pseudonymization replaces direct identifiers with codes (re-linkable with a key), while anonymization irreversibly removes all identifying information.

  5. Which of the following is a key requirement of a records security program for vital records?

    Answer: Vital records must be identified, duplicated, and protected to ensure organizational continuity

    Vital records programs require identification, duplication, and secure off-site or redundant storage to ensure continuity of operations after a disaster.

  6. A records manager receives a legal hold notice. What action regarding information security should be taken IMMEDIATELY?

    Answer: Suspend normal disposition and ensure all potentially relevant records are preserved and protected from alteration

    A legal hold supersedes normal retention schedules, requiring immediate preservation and protection of relevant records from any deletion or modification.

  7. Which concept describes the practice of building privacy protections into systems and processes from the start, rather than adding them later?

    Answer: Privacy by design

    Privacy by design embeds privacy protections into the architecture of systems and business practices from the outset, not as an afterthought.