GRC Data Privacy and Information Governance Flashcards
6 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 GRC Data Privacy and Information Governance flashcards as text
Which framework provides guidance specifically for managing privacy-related risks as a complement to the NIST Cybersecurity Framework?
Answer: NIST Privacy Framework
The NIST Privacy Framework was developed to help organizations identify and manage privacy risk and is designed to work alongside the NIST Cybersecurity Framework.
A 'breach notification' requirement under U.S. state data breach laws generally obligates organizations to:
Answer: Notify affected individuals and sometimes regulators within a specified timeframe after discovering a data breach
U.S. state breach notification laws typically require timely notification to affected individuals and relevant regulatory authorities when personal data is compromised.
The concept of 'Privacy by Design' primarily means:
Answer: Embedding privacy protections into systems and processes from the outset
Privacy by Design advocates for proactively integrating data privacy into the architecture of IT systems and business practices rather than treating it as an afterthought.
Under the FTC Act, the FTC has authority to take action against companies for unfair or deceptive privacy practices under which section?
Answer: Section 5
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in commerce, which the FTC uses as its primary authority to enforce consumer data privacy.
Which of the following is a key component of an effective data retention and disposal policy?
Answer: Defining specific retention periods tied to legal, regulatory, and business requirements and securely destroying data when those periods expire
An effective data retention policy specifies how long each data category must be kept based on applicable requirements and ensures secure, verifiable disposal once the period ends.
In GRC information governance, 'metadata management' involves:
Answer: Organizing and maintaining data about data to improve discoverability, quality, and compliance
Metadata management is the discipline of governing descriptive, structural, and administrative information about data assets to support data quality and regulatory compliance.