CCB Data Privacy & Information Security Compliance Flashcards
6 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCB Data Privacy & Information Security Compliance flashcards as text
What does 'right to opt-out' mean under CCPA for California residents?
Answer: The right to stop a business from selling their personal information to third parties
Under CCPA, the right to opt-out allows California consumers to direct businesses not to sell their personal information to third parties.
In U.S. compliance, which type of data is specifically protected under COPPA?
Answer: Personal information of children under 13
The Children's Online Privacy Protection Act (COPPA) protects the personal information of children under the age of 13 collected online, requiring verifiable parental consent.
Which of the following is a key requirement of the FTC Safeguards Rule for non-banking financial institutions?
Answer: Designating a qualified individual to oversee the information security program
The updated FTC Safeguards Rule requires covered financial institutions to designate a qualified individual responsible for overseeing, implementing, and enforcing the information security program.
What is the standard for determining whether a data breach requires notification to affected individuals under most U.S. state breach notification laws?
Answer: Unauthorized acquisition of unencrypted personal information that poses a risk of harm
Most U.S. state breach notification laws trigger notification when there is unauthorized acquisition of unencrypted personal information that creates a material risk of harm to affected individuals.
In an information security compliance program, what is the role of a 'Business Continuity Plan' (BCP)?
Answer: To ensure critical business functions can continue during and after a disruption
A Business Continuity Plan (BCP) defines how an organization will maintain essential operations during a crisis or disruption, minimizing the impact on customers and regulatory obligations.
Which concept requires that employees only have access to the data and systems needed to perform their specific job functions?
Answer: Least privilege principle
The least privilege principle limits user access rights to only the minimum permissions required for their role, reducing the risk of unauthorized data access or insider threats.