โ† All CDPSE Flashcard Decks

Governance Frameworks Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance Frameworks flashcards as text
  1. Which NIST privacy framework function focuses on developing organizational understanding to manage privacy risk to individuals?

    Answer: Identify-P

    The Identify-P function in the NIST Privacy Framework establishes understanding of data processing activities and associated privacy risks.

  2. An organization adopts ISO 29100 as part of its governance framework. Which of the following does ISO 29100 primarily provide?

    Answer: A privacy framework defining principles and terminology for PII protection

    ISO 29100 provides a high-level privacy framework with principles and terminology for the protection of personally identifiable information.

  3. What is the primary purpose of conducting a privacy maturity assessment within a governance program?

    Answer: To benchmark current capabilities against a defined model and identify gaps

    A privacy maturity assessment benchmarks existing practices against a capability model, revealing gaps and prioritizing improvements.

  4. In privacy governance, a RACI matrix is used to:

    Answer: Define who is Responsible, Accountable, Consulted, and Informed for privacy activities

    A RACI matrix clarifies roles and ownership for privacy tasks, preventing accountability gaps and duplication of effort.

  5. Which governance mechanism allows organizations to demonstrate ongoing compliance rather than point-in-time compliance with privacy requirements?

    Answer: Continuous monitoring and periodic privacy reviews

    Continuous monitoring and periodic reviews provide ongoing assurance that controls remain effective as organizational and regulatory conditions change.

  6. A privacy governance framework should ensure that privacy requirements are embedded into the system development lifecycle (SDLC) through which practice?

    Answer: Privacy by Design integration at each SDLC phase

    Privacy by Design embeds privacy controls and requirements at every SDLC phase rather than retrofitting them after development.

  7. Which metric would BEST indicate the effectiveness of a privacy governance program over time?

    Answer: Reduction in confirmed privacy incidents and sustained regulatory compliance rates

    Outcome-based metrics like incident reduction and compliance rates directly measure governance program effectiveness.