CIP Information Governance and Strategy 3 — Questions and Answers
Question 1: In the context of CIP, 'information stewardship' refers to:
- Accountability for managing information assets on behalf of the organization (Correct answer)
- The IT department's responsibility for server maintenance
- Archiving paper records in off-site storage
- Drafting contracts with cloud service providers
Correct answer: Accountability for managing information assets on behalf of the organization
Stewardship is the responsibility to manage information assets carefully and ethically in service of organizational and stakeholder needs.
Question 2: A 'litigation hold' (also called a legal hold) requires an organization to:
- Suspend normal disposition of records potentially relevant to anticipated litigation (Correct answer)
- Encrypt all records above a certain sensitivity level
- Restrict access to records to legal department staff only
- Immediately destroy records not relevant to the lawsuit
Correct answer: Suspend normal disposition of records potentially relevant to anticipated litigation
A litigation hold overrides retention schedules to preserve all potentially relevant information until legal proceedings conclude.
Question 3: Which framework specifically addresses information governance for healthcare organizations in the United States?
- HIPAA (Correct answer)
- SOX
- GDPR
- FERPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets the IG and privacy standards for protected health information in US healthcare.
Question 4: A data classification scheme that uses labels such as 'Public,' 'Internal,' 'Confidential,' and 'Restricted' supports IG by:
- Enabling consistent, risk-appropriate handling policies for each category (Correct answer)
- Automatically encrypting all files upon creation
- Replacing the need for access control lists
- Satisfying all regulatory retention requirements automatically
Correct answer: Enabling consistent, risk-appropriate handling policies for each category
Classification labels allow organizations to apply differentiated security, access, and handling rules proportional to information sensitivity.
Question 5: What is the primary purpose of an Information Governance Reference Model (IGRM)?
- To illustrate how legal, IT, records, privacy, and business functions share responsibility for information (Correct answer)
- To replace an organization's existing ERM system
- To serve as a technical architecture blueprint for data warehouses
- To define mandatory retention periods for all record types
Correct answer: To illustrate how legal, IT, records, privacy, and business functions share responsibility for information
The IGRM visually maps how different organizational functions must collaborate to govern information across its life cycle.
Question 6: Which of the following best describes 'dark data' in an enterprise context?
- Information collected and stored but never analyzed or used for business value (Correct answer)
- Classified government records stored in secure vaults
- Encrypted data that has lost its decryption key
- Data backups stored in geographically remote locations
Correct answer: Information collected and stored but never analyzed or used for business value
Dark data refers to the large volumes of information organizations collect and retain but do not actively use, creating storage cost and risk without benefit.
Question 7: An organization wants to align its IG program with ISO 15489. This standard primarily addresses:
- Records management principles and processes (Correct answer)
- Information security management systems
- IT service management best practices
- Business continuity planning
Correct answer: Records management principles and processes
ISO 15489 is the international standard for records management, covering principles for creating, capturing, and managing records.
In the context of CIP, 'information stewardship' refers to: