CRCM Privacy and Data Security Compliance 2 — Questions and Answers
Question 1: Under the interagency guidelines for safeguarding customer information, financial institutions must conduct which activity to identify risks to customer data?
- An annual external penetration test only
- A risk assessment to identify reasonably foreseeable risks (Correct answer)
- A customer survey on data handling preferences
- A quarterly review of employee social media accounts
Correct answer: A risk assessment to identify reasonably foreseeable risks
The interagency guidelines require financial institutions to conduct a risk assessment to identify and evaluate internal and external risks to customer data security.
Question 2: When a financial institution discovers a 'notification incident' involving customer data, current OCC/FDIC guidance requires notification to the primary federal regulator within:
- 24 hours
- 36 hours (Correct answer)
- 72 hours
- 30 days
Correct answer: 36 hours
The interagency computer-security incident notification rules require banks to notify their primary federal regulator within 36 hours of determining a notification incident occurred.
Question 3: The Right to Financial Privacy Act (RFPA) restricts federal government agencies from obtaining customer financial records without:
- Board of directors approval
- Customer notice or legal process such as a subpoena (Correct answer)
- Regulatory approval from the OCC
- Written authorization from FinCEN
Correct answer: Customer notice or legal process such as a subpoena
The RFPA requires federal government agencies to either notify the customer or use legal process (e.g., subpoena, court order) before obtaining financial records.
Question 4: Under the GLBA Safeguards Rule, covered institutions must test or monitor the effectiveness of their security controls:
- Only when they experience a breach
- Regularly, as part of the information security program (Correct answer)
- Every five years via third-party audit
- Only if directed to do so by an examiner
Correct answer: Regularly, as part of the information security program
The Safeguards Rule requires regular testing and monitoring of key controls and systems to ensure they are effective and up to date.
Question 5: What is the purpose of a 'clean desk policy' in a bank's information security program?
- To enforce uniform branch appearance standards
- To prevent unauthorized access to sensitive information left unattended in work areas (Correct answer)
- To comply with OSHA workplace safety regulations
- To reduce paper usage and support sustainability goals
Correct answer: To prevent unauthorized access to sensitive information left unattended in work areas
A clean desk policy requires employees to secure sensitive documents and data when leaving their workstations, reducing risk of unauthorized access.
Question 6: Which privacy concept requires that personal data be used only for the purposes for which it was originally collected?
- Data minimization
- Purpose limitation (Correct answer)
- Data portability
- Retention scheduling
Correct answer: Purpose limitation
Purpose limitation is the principle that personal data should only be processed for the specific purposes disclosed at the time of collection.
Under the interagency guidelines for safeguarding customer information, financial institutions must conduct which activity to identify risks to customer data?