โ† All CIA Flashcard Decks

Information Governance and Maintenance Flashcards

7 cards from real CIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Governance and Maintenance flashcards as text
  1. Under GDPR, which information governance obligation requires organizations to document what personal data they hold, where it is stored, and how it is used?

    Answer: Records of processing activities (Article 30)

    Article 30 of GDPR mandates that controllers maintain records of processing activities, which is a core information governance accountability requirement.

  2. What distinguishes a data governance policy from a data governance standard?

    Answer: Policies state what must be achieved; standards define how to achieve it consistently

    Policies express high-level mandatory intentions (the 'what'), while standards provide specific, measurable requirements for how to comply (the 'how').

  3. Which approach best supports continuous data quality improvement within a governance program?

    Answer: Ongoing data quality KPIs monitored by stewards with escalation paths

    Continuous monitoring with KPIs and escalation ensures issues are detected and resolved as they occur rather than accumulating until a periodic audit.

  4. An information architect must choose between active and passive metadata management strategies. What is the key difference?

    Answer: Active metadata management dynamically updates and uses metadata to drive processes; passive simply stores it

    Active metadata management uses metadata operationally to automate governance tasks such as lineage tracking and policy enforcement, unlike passive storage-only approaches.

  5. Which data lifecycle phase is most critical to govern in order to prevent accumulation of unnecessary sensitive data (data minimization)?

    Answer: Data creation/ingestion

    Governing data at creation or ingestion prevents unnecessary sensitive data from entering systems, directly enforcing data minimization at the source.

  6. What is the purpose of a data stewardship escalation path in an information governance framework?

    Answer: To provide a structured mechanism for resolving data issues that stewards cannot resolve independently

    An escalation path ensures unresolved data issues or policy conflicts move to higher authority levels for timely, authoritative resolution.

  7. Which governance control helps ensure that changes to critical reference data (e.g., product codes, country codes) are reviewed before being applied?

    Answer: Change control process for reference data

    A change control process for reference data requires review and approval before updates, preventing unauthorized or erroneous changes that cascade across systems.