CLM Legal Technology & Information Management 2 — Questions and Answers
Question 1: Which cloud computing model is most commonly recommended for law firms handling sensitive client data due to its dedicated infrastructure?
- Public cloud
- Community cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud provides dedicated infrastructure for a single organization, offering greater control and security for sensitive legal client data.
Question 2: The EDRM (Electronic Discovery Reference Model) framework outlines the e-discovery process in what general order?
- Review → Collect → Process → Produce
- Information Governance → Identify → Preserve → Collect → Process → Review → Analyze → Produce → Present (Correct answer)
- Collect → Preserve → Review → Analyze → Produce
- Preserve → Collect → Analyze → Review → Present
Correct answer: Information Governance → Identify → Preserve → Collect → Process → Review → Analyze → Produce → Present
The EDRM framework flows from Information Governance through Identification, Preservation, Collection, Processing, Review, Analysis, Production, and Presentation.
Question 3: Which of the following best describes a Document Management System (DMS) used in law firms?
- Software that automates court filings
- A system for organizing, storing, tracking, and retrieving legal documents (Correct answer)
- A billing platform integrated with accounting software
- A client relationship management tool
Correct answer: A system for organizing, storing, tracking, and retrieving legal documents
A DMS organizes, stores, tracks versions, and retrieves legal documents, providing a centralized repository for a firm's document library.
Question 4: Under HIPAA, law firms that handle protected health information (PHI) on behalf of healthcare clients are classified as:
- Covered entities
- Business associates (Correct answer)
- Hybrid entities
- Clearinghouses
Correct answer: Business associates
Law firms handling PHI on behalf of healthcare covered entities are classified as business associates under HIPAA and must sign a Business Associate Agreement (BAA).
Question 5: What is the purpose of a Records Retention Schedule in a law firm?
- To schedule client meetings and court appearances
- To define how long different categories of records must be kept and when they can be destroyed (Correct answer)
- To track billable hours for records management staff
- To organize files by attorney assignment
Correct answer: To define how long different categories of records must be kept and when they can be destroyed
A Records Retention Schedule identifies categories of records, the required retention period (based on legal, regulatory, and business needs), and the authorized destruction date.
Question 6: Which cybersecurity framework is most widely referenced for assessing and improving law firm information security programs?
- ISO 9001
- NIST Cybersecurity Framework (Correct answer)
- COBIT 5
- ITIL v4
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides standards, guidelines, and best practices for managing cybersecurity risk and is widely referenced by law firms.
Question 7: A law firm's IT acceptable use policy (AUP) primarily serves to:
- Authorize IT staff to monitor all employee communications without restriction
- Define rules for appropriate use of firm technology resources and establish user responsibilities (Correct answer)
- Grant employees unlimited access to firm systems from personal devices
- Outsource cybersecurity responsibilities to employees
Correct answer: Define rules for appropriate use of firm technology resources and establish user responsibilities
An AUP defines the rules and restrictions for acceptable use of a firm's technology assets and clarifies employee responsibilities to protect firm information.
Which cloud computing model is most commonly recommended for law firms handling sensitive client data due to its dedicated infrastructure?