Compliance Standards Flashcards
7 cards from real CDIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Standards flashcards as text
Which standard defines the archival quality requirements for PDF files intended for long-term preservation, commonly used in compliant document imaging systems?
Answer: PDF/A (ISO 19005)
PDF/A (ISO 19005) is the ISO standard for long-term archival of PDF documents, restricting features that would impede future rendering.
A CDIA practitioner is designing a system for a law firm. Which compliance principle requires that confidential client documents be inaccessible to attorneys not assigned to that matter?
Answer: Ethical wall (information barrier)
An ethical wall (also called a Chinese wall or information barrier) prevents attorneys and staff from accessing client files where a conflict of interest exists.
Under the E-SIGN Act (Electronic Signatures in Global and National Commerce Act), what must an electronic signature do to be legally valid?
Answer: Demonstrate the signer's intent to sign and be logically associated with the signed record
The E-SIGN Act requires that an electronic signature demonstrate intent to sign and be associated with the contract or record being signed — no specific technology is mandated.
When implementing document imaging for a government contractor, which regulation governs the protection of Controlled Unclassified Information (CUI) in non-federal systems?
Answer: NIST SP 800-171
NIST SP 800-171 specifies requirements for protecting CUI in non-federal information systems and organizations, including contractor environments.
What is the purpose of a 'file plan' in a records management compliance program?
Answer: A structured classification scheme that organizes records into categories with associated retention and disposition instructions
A file plan organizes an organization's records into a logical hierarchy, mapping each record series to its retention schedule and disposition instructions.
A company subject to the California Consumer Privacy Act (CCPA) receives a consumer request to delete their personal information from the document imaging system. Under CCPA, this is known as the:
Answer: Right to Erasure (Right to Delete)
CCPA's Right to Delete allows consumers to request businesses delete their personal information, subject to certain exceptions.
In the context of document imaging compliance, what does 'defensible deletion' mean?
Answer: The systematic, policy-driven destruction of records that have met their retention period and are not under legal hold, supported by documented procedures
Defensible deletion means destroying records per documented retention policies with proper authorization, creating a legally defensible justification for their absence.