CDT Security & Privacy in Document Management 3 — Questions and Answers
Question 1: Which privacy regulation requires organizations to obtain explicit consent before processing personal data of EU residents, even when the organization is based in the US?
- SOX
- GDPR (Correct answer)
- FERPA
- GLBA
Correct answer: GDPR
The General Data Protection Regulation (GDPR) has extraterritorial reach and applies to any organization processing personal data of EU residents.
Question 2: What is 'chain of custody' as it applies to document security?
- A signing process for contracts
- A documented record tracking who handled a document, when, and for what purpose (Correct answer)
- The order in which documents are filed
- A method for encrypting file transfers
Correct answer: A documented record tracking who handled a document, when, and for what purpose
Chain of custody is an audit trail proving documents have not been tampered with, critical for legal admissibility and regulatory compliance.
Question 3: A records manager discovers that confidential HR files are stored in a shared folder accessible to all employees. This is an example of which security failure?
- Inadequate backup procedures
- Excessive access privileges / broken access control (Correct answer)
- Missing metadata tagging
- Improper retention scheduling
Correct answer: Excessive access privileges / broken access control
Storing sensitive files in broadly accessible locations violates access control principles and exposes confidential information to unauthorized users.
Question 4: Under SOX Section 802, what is the criminal penalty for knowingly altering or destroying documents that are relevant to a federal investigation?
- Civil fine only
- Up to 5 years in prison
- Up to 20 years in prison (Correct answer)
- License revocation only
Correct answer: Up to 20 years in prison
SOX Section 802 imposes criminal penalties of up to 20 years imprisonment for knowingly destroying or falsifying documents in federal proceedings.
Question 5: Which control best prevents a terminated employee's credentials from being used to access the document management system?
- Requiring complex passwords
- Immediate account deprovisioning upon termination (Correct answer)
- Mandatory annual access reviews
- Encrypting all HR records
Correct answer: Immediate account deprovisioning upon termination
Immediate deprovisioning removes access the moment employment ends, preventing any window during which a disgruntled or former employee could misuse credentials.
Question 6: What is the key difference between authentication and authorization in document security?
- Authentication determines what you can do; authorization confirms who you are
- Authentication confirms who you are; authorization determines what you can do (Correct answer)
- They are interchangeable terms in document management
- Authentication applies only to physical documents
Correct answer: Authentication confirms who you are; authorization determines what you can do
Authentication verifies identity (who you are), while authorization determines what resources and actions that identity is permitted to access.
Question 7: A company scans and stores all paper documents electronically, then shreds the originals. Which standard addresses the legal admissibility of such electronic records?
- ISO 9001
- ANSI/AIIM MS23 / NARA guidelines (Correct answer)
- PCI DSS
- RFC 2822
Correct answer: ANSI/AIIM MS23 / NARA guidelines
ANSI/AIIM MS23 and NARA guidelines provide standards for digitization quality and procedures that support the legal admissibility of scanned electronic records.
Which privacy regulation requires organizations to obtain explicit consent before processing personal data of EU residents, even when the organization is based in the US?