CRM Information Security & Privacy 1 — Questions and Answers
Question 1: What is the primary goal of information security?
- To increase data volume.
- To improve aesthetics.
- To ensure data is protected from unauthorized access or changes. (Correct answer)
- To print more paper files.
Correct answer: To ensure data is protected from unauthorized access or changes.
The primary goal of information security is to protect the confidentiality, integrity, and availability (CIA triad) of information assets. This means safeguarding data from unauthorized access, use, disclosure, disruption, modification, or destruction. Effective information security measures are crucial for maintaining trust, complying with regulations, and protecting an organization's valuable data.
Question 2: Which method helps secure digital records?
- Rewriting files weekly.
- Disabling antivirus software.
- Encrypting sensitive data. (Correct answer)
- Printing digital records regularly.
Correct answer: Encrypting sensitive data.
Encrypted sensitive data is a fundamental method for securing digital records. Encryption transforms data into a coded format, making it unreadable to anyone without the correct decryption key. This protects information both in transit and at rest, ensuring that even if unauthorized individuals gain access to the data, they cannot understand or use it.
Question 3: What is 'least privilege' in access control?
- Allowing full access to all users.
- Limiting access to only necessary data. (Correct answer)
- Revoking admin rights for IT staff.
- Giving access based on age.
Correct answer: Limiting access to only necessary data.
The principle of 'least privilege' in access control dictates that users, programs, or processes should be granted only the minimum level of access permissions necessary to perform their specific tasks. This minimizes the potential damage from accidental errors, misuse, or malicious activity, as it restricts what an unauthorized individual or compromised account can access or alter.
Question 4: What should organizations do to manage privacy risks?
- Collect as much personal data as possible.
- Avoid using passwords.
- Conduct privacy impact assessments. (Correct answer)
- Ignore data subject rights.
Correct answer: Conduct privacy impact assessments.
To effectively manage privacy risks, organizations should conduct Privacy Impact Assessments (PIAs) or Data Protection Impact Assessments (DPIAs). These assessments systematically identify and evaluate potential privacy risks associated with new projects, systems, or data processing activities. They help organizations implement appropriate safeguards and ensure compliance with privacy regulations before issues arise.
Question 5: Why is multi-factor authentication important?
- It slows down users.
- It increases login errors.
- It enhances account protection with multiple verification methods. (Correct answer)
- It eliminates passwords completely.
Correct answer: It enhances account protection with multiple verification methods.
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more verification factors to gain access to an account or system. These factors typically include something the user knows (like a password), something the user has (like a phone or token), and something the user is (like a fingerprint). This layered approach makes it much harder for unauthorized individuals to compromise accounts, even if they steal a password.
Question 6: How should sensitive paper records be disposed?
- Thrown in public bins.
- Stored in unlocked cabinets.
- Recycled without review.
- Shredded or destroyed securely. (Correct answer)
Correct answer: Shredded or destroyed securely.
Sensitive paper records contain confidential or personal information that, if exposed, could lead to privacy breaches or identity theft. Therefore, they must be disposed of securely, typically through shredding, pulping, or incineration, to render the information unreadable and irrecoverable. This prevents unauthorized access and ensures compliance with data protection regulations.
Question 7: What is the purpose of a data breach response plan?
- To increase data collection.
- To delay breach reporting.
- To address and mitigate data breach incidents. (Correct answer)
- To notify competitors.
Correct answer: To address and mitigate data breach incidents.
A data breach response plan is a critical component of an organization's information security strategy. Its purpose is to provide a structured, pre-defined set of actions to be taken immediately following a data breach incident. This plan helps an organization quickly contain the breach, assess its impact, notify affected parties, and implement remediation steps to minimize damage and restore security.
Question 8: What is considered personally identifiable information (PII)?
- Weather forecasts.
- Company policies.
- Names, social security numbers, and email addresses. (Correct answer)
- Public announcements.
Correct answer: Names, social security numbers, and email addresses.
Personally Identifiable Information (PII) refers to data that can be used to identify, contact, or locate a single person, or to identify an individual in context. Names, social security numbers, and email addresses are direct identifiers that, alone or combined, can uniquely pinpoint an individual. Protecting PII is crucial for privacy and security compliance.
Question 9: Why is employee training essential for information security?
- It increases administrative tasks.
- It replaces software updates.
- It helps staff recognize and avoid security risks. (Correct answer)
- It encourages data sharing.
Correct answer: It helps staff recognize and avoid security risks.
Employee training is essential for information security because human error is a leading cause of security breaches. Training equips staff with the knowledge to recognize phishing attempts, understand data handling protocols, and follow security best practices. This proactive approach significantly reduces the risk of security incidents by fostering a security-aware culture.
What is the primary goal of information security?