CIPM CIPM Privacy Risk Management 2 — Questions and Answers
Question 1: Which four options are commonly used to treat privacy risks identified during a risk assessment?
- Avoid, mitigate, transfer, and accept (Correct answer)
- Identify, assess, remediate, and report
- Detect, respond, recover, and review
- Encrypt, pseudonymize, anonymize, and delete
Correct answer: Avoid, mitigate, transfer, and accept
The four standard risk treatment options are: avoid (stop the risky activity), mitigate (reduce the risk), transfer (share risk via insurance or contracts), and accept (acknowledge and proceed with residual risk).
Question 2: What is the primary goal of threat modeling in a privacy risk management context?
- To identify potential threats to personal data and design controls before they are exploited (Correct answer)
- To respond to active data breaches in real time
- To audit vendor privacy practices
- To train employees on phishing awareness
Correct answer: To identify potential threats to personal data and design controls before they are exploited
Threat modeling proactively identifies potential adversaries, attack vectors, and vulnerabilities that could compromise personal data, enabling the design of appropriate preventive controls.
Question 3: Which NIST Special Publication provides a catalog of security and privacy controls for federal information systems?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-61
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls that federal agencies and contractors can use to protect information systems and personal data.
Question 4: What is the purpose of a privacy threshold assessment (PTA)?
- To determine whether a full PIA or DPIA is required for a given project (Correct answer)
- To calculate the financial cost of a privacy breach
- To assess vendor compliance with contractual privacy terms
- To evaluate employee adherence to privacy policies
Correct answer: To determine whether a full PIA or DPIA is required for a given project
A privacy threshold assessment is a preliminary screening tool that evaluates whether a proposed project or system involves sufficient privacy risk to warrant a full PIA or DPIA.
Question 5: How does an organization's 'risk appetite' influence its privacy program decisions?
- It defines the level of risk the organization is willing to accept before taking additional action (Correct answer)
- It determines the number of privacy staff required
- It sets the budget for privacy training
- It specifies which data subjects can exercise their rights
Correct answer: It defines the level of risk the organization is willing to accept before taking additional action
Risk appetite establishes the threshold of acceptable risk, guiding decisions on which privacy risks require treatment and which residual risks can be tolerated without further controls.
Question 6: What is the primary role of a Data Protection Officer (DPO) in an organization's privacy risk management program?
- To advise on and monitor compliance with data protection laws and serve as a contact point for supervisory authorities (Correct answer)
- To approve all data processing contracts
- To conduct technical security penetration tests
- To manage the organization's incident response team
Correct answer: To advise on and monitor compliance with data protection laws and serve as a contact point for supervisory authorities
Under GDPR Article 39, the DPO's tasks include informing and advising the controller and processors, monitoring compliance, advising on DPIAs, and cooperating with supervisory authorities.
Which four options are commonly used to treat privacy risks identified during a risk assessment?