CCB Data Privacy & Information Security Compliance Flashcards
6 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCB Data Privacy & Information Security Compliance flashcards as text
Under the California Consumer Privacy Act (CCPA), what right allows consumers to request deletion of their personal information?
Answer: Right to erasure
The CCPA grants consumers the right to request deletion (erasure) of personal information collected by a business, subject to certain exceptions.
Which U.S. federal law establishes minimum data security standards for financial institutions, including safeguard rules for customer information?
Answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to implement safeguards to protect customers' nonpublic personal information.
A data breach notification requirement typically mandates reporting within how many hours under U.S. federal banking regulations?
Answer: 36 hours
The FFIEC/OCC Computer-Security Incident Notification Rule requires banking organizations to notify their primary federal regulator within 36 hours of discovering a significant cybersecurity incident.
Which of the following best describes 'data minimization' as a privacy compliance principle?
Answer: Collecting only data necessary for a specific purpose
Data minimization requires organizations to collect only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
In the context of information security compliance, what does a 'data inventory' primarily help an organization accomplish?
Answer: Map where personal data is collected, stored, and shared
A data inventory (or data map) identifies what personal data an organization holds, where it resides, how it flows, and who has access — foundational to privacy compliance.
Which framework is most commonly used by U.S. organizations to assess and improve cybersecurity risk management practices?
Answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach to managing cybersecurity risk and is widely adopted by U.S. organizations across industries.