CGRC CGRC Privacy and Data Protection 1 — Questions and Answers
Question 1: Which U.S. federal law establishes privacy and security requirements for federal agencies' handling of personally identifiable information (PII)?
- HIPAA
- The Privacy Act of 1974 (Correct answer)
- GLBA
- COPPA
Correct answer: The Privacy Act of 1974
The Privacy Act of 1974 governs how federal agencies collect, maintain, use, and disclose PII about individuals, granting citizens rights over their records.
Question 2: What is Personally Identifiable Information (PII) as defined by NIST?
- Any data stored on a federal system regardless of sensitivity
- Information that can be used to distinguish or trace an individual's identity (Correct answer)
- Encrypted data that has been anonymized
- Technical system configuration data
Correct answer: Information that can be used to distinguish or trace an individual's identity
NIST defines PII as any information that can be used alone or in combination with other information to identify, contact, or locate a specific individual.
Question 3: What document must federal agencies publish to notify the public about a system that collects and maintains PII?
- System Security Plan (SSP)
- System of Records Notice (SORN) (Correct answer)
- Privacy Impact Assessment (PIA)
- Data Flow Diagram (DFD)
Correct answer: System of Records Notice (SORN)
A System of Records Notice (SORN) is published in the Federal Register to inform the public about a system that retrieves records by personal identifiers.
Question 4: Under the CGRC framework, which assessment evaluates privacy risks associated with collecting, storing, and using PII in a federal system?
- Business Impact Analysis (BIA)
- Privacy Impact Assessment (PIA) (Correct answer)
- Security Assessment Report (SAR)
- Risk Assessment Report (RAR)
Correct answer: Privacy Impact Assessment (PIA)
A Privacy Impact Assessment (PIA) analyzes how PII is collected, used, shared, and protected, identifying and mitigating privacy risks.
Question 5: Which NIST SP 800-53 control family specifically addresses privacy requirements integrated into the security control framework?
- PT – PII Processing and Transparency (Correct answer)
- AC – Access Control
- AT – Awareness and Training
- MP – Media Protection
Correct answer: PT – PII Processing and Transparency
NIST SP 800-53 Rev. 5 introduced the PT (PII Processing and Transparency) family, which includes controls for consent, purpose specification, and data minimization.
Question 6: What is the principle of data minimization in the context of privacy protection?
- Encrypting all PII using the strongest available algorithm
- Collecting and retaining only the minimum amount of PII necessary for the stated purpose (Correct answer)
- Storing PII in the fewest number of databases possible
- Limiting access to PII to only one authorized user
Correct answer: Collecting and retaining only the minimum amount of PII necessary for the stated purpose
Data minimization requires that organizations collect only the PII that is directly relevant and necessary to accomplish the specified purpose, reducing exposure risk.
Which U.S. federal law establishes privacy and security requirements for federal agencies' handling of personally identifiable information (PII)?