CDPSE Governance Frameworks 3 — Questions and Answers
Question 1: Which NIST privacy framework function focuses on developing organizational understanding to manage privacy risk to individuals?
- Respond
- Communicate
- Identify-P (Correct answer)
- Protect-P
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework establishes understanding of data processing activities and associated privacy risks.
Question 2: An organization adopts ISO 29100 as part of its governance framework. Which of the following does ISO 29100 primarily provide?
- Specific technical controls for database encryption
- A privacy framework defining principles and terminology for PII protection (Correct answer)
- Mandatory certification requirements for cloud providers
- Detailed audit procedures for privacy assessments
Correct answer: A privacy framework defining principles and terminology for PII protection
ISO 29100 provides a high-level privacy framework with principles and terminology for the protection of personally identifiable information.
Question 3: What is the primary purpose of conducting a privacy maturity assessment within a governance program?
- To satisfy annual regulatory filing requirements
- To benchmark current capabilities against a defined model and identify gaps (Correct answer)
- To eliminate the need for future privacy audits
- To transfer privacy liability to assessment vendors
Correct answer: To benchmark current capabilities against a defined model and identify gaps
A privacy maturity assessment benchmarks existing practices against a capability model, revealing gaps and prioritizing improvements.
Question 4: In privacy governance, a RACI matrix is used to:
- Classify data by sensitivity level
- Define who is Responsible, Accountable, Consulted, and Informed for privacy activities (Correct answer)
- Record and track data subject access requests
- Map data flows across organizational systems
Correct answer: Define who is Responsible, Accountable, Consulted, and Informed for privacy activities
A RACI matrix clarifies roles and ownership for privacy tasks, preventing accountability gaps and duplication of effort.
Question 5: Which governance mechanism allows organizations to demonstrate ongoing compliance rather than point-in-time compliance with privacy requirements?
- One-time privacy audits
- Continuous monitoring and periodic privacy reviews (Correct answer)
- Annual employee privacy training only
- Single vendor risk assessments
Correct answer: Continuous monitoring and periodic privacy reviews
Continuous monitoring and periodic reviews provide ongoing assurance that controls remain effective as organizational and regulatory conditions change.
Question 6: A privacy governance framework should ensure that privacy requirements are embedded into the system development lifecycle (SDLC) through which practice?
- Post-launch penetration testing
- Privacy by Design integration at each SDLC phase (Correct answer)
- End-user training on new features
- Third-party code reviews only
Correct answer: Privacy by Design integration at each SDLC phase
Privacy by Design embeds privacy controls and requirements at every SDLC phase rather than retrofitting them after development.
Question 7: Which metric would BEST indicate the effectiveness of a privacy governance program over time?
- Number of privacy policies published
- Reduction in confirmed privacy incidents and sustained regulatory compliance rates (Correct answer)
- Size of the privacy team headcount
- Volume of privacy training materials produced
Correct answer: Reduction in confirmed privacy incidents and sustained regulatory compliance rates
Outcome-based metrics like incident reduction and compliance rates directly measure governance program effectiveness.
Which NIST privacy framework function focuses on developing organizational understanding to manage privacy risk to individuals?