โ† All CDT Flashcard Decks

Security & Privacy in Document Management Flashcards

7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Privacy in Document Management flashcards as text
  1. Which privacy regulation requires organizations to obtain explicit consent before processing personal data of EU residents, even when the organization is based in the US?

    Answer: GDPR

    The General Data Protection Regulation (GDPR) has extraterritorial reach and applies to any organization processing personal data of EU residents.

  2. What is 'chain of custody' as it applies to document security?

    Answer: A documented record tracking who handled a document, when, and for what purpose

    Chain of custody is an audit trail proving documents have not been tampered with, critical for legal admissibility and regulatory compliance.

  3. A records manager discovers that confidential HR files are stored in a shared folder accessible to all employees. This is an example of which security failure?

    Answer: Excessive access privileges / broken access control

    Storing sensitive files in broadly accessible locations violates access control principles and exposes confidential information to unauthorized users.

  4. Under SOX Section 802, what is the criminal penalty for knowingly altering or destroying documents that are relevant to a federal investigation?

    Answer: Up to 20 years in prison

    SOX Section 802 imposes criminal penalties of up to 20 years imprisonment for knowingly destroying or falsifying documents in federal proceedings.

  5. Which control best prevents a terminated employee's credentials from being used to access the document management system?

    Answer: Immediate account deprovisioning upon termination

    Immediate deprovisioning removes access the moment employment ends, preventing any window during which a disgruntled or former employee could misuse credentials.

  6. What is the key difference between authentication and authorization in document security?

    Answer: Authentication confirms who you are; authorization determines what you can do

    Authentication verifies identity (who you are), while authorization determines what resources and actions that identity is permitted to access.

  7. A company scans and stores all paper documents electronically, then shreds the originals. Which standard addresses the legal admissibility of such electronic records?

    Answer: ANSI/AIIM MS23 / NARA guidelines

    ANSI/AIIM MS23 and NARA guidelines provide standards for digitization quality and procedures that support the legal admissibility of scanned electronic records.