โ† All CCB Flashcard Decks

CCB Data Privacy & Information Security Compliance Flashcards

6 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCB Data Privacy & Information Security Compliance flashcards as text
  1. Under HIPAA's Security Rule, which type of safeguard includes workforce training and security policies?

    Answer: Administrative safeguards

    HIPAA's Administrative Safeguards include policies, procedures, workforce training, and security management processes designed to protect electronic protected health information (ePHI).

  2. What is the primary purpose of a Privacy Impact Assessment (PIA) in a compliance program?

    Answer: To evaluate privacy risks of a new project or system before implementation

    A Privacy Impact Assessment (PIA) systematically identifies and evaluates privacy risks associated with a new project, system, or process before it is deployed.

  3. Which term refers to the contractual obligation requiring a vendor who processes personal data on behalf of a company to follow the company's privacy requirements?

    Answer: Data Processing Agreement (DPA)

    A Data Processing Agreement (DPA) legally binds a third-party vendor (data processor) to handle personal data in accordance with the data controller's privacy obligations and applicable law.

  4. What is 'pseudonymization' as used in data privacy compliance?

    Answer: Replacing identifying fields with artificial identifiers so data cannot be attributed to an individual without additional information

    Pseudonymization replaces direct identifiers with artificial codes, reducing privacy risk while still allowing data to be re-linked if needed with separately held key information.

  5. A company experiences a ransomware attack that encrypts customer data. Under the FTC's data security expectations, which response is most appropriate first?

    Answer: Activate the incident response plan and contain the breach

    Best practice and regulatory expectation require activating the incident response plan to contain the breach, assess the impact, and follow proper notification protocols before other actions.

  6. Which principle requires organizations to implement data protection measures from the outset of designing a product or service?

    Answer: Privacy by Design

    Privacy by Design mandates that data protection and privacy are built into systems and processes from the earliest design stage, rather than added as an afterthought.