GRC Data Privacy and Information Governance Flashcards
6 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 GRC Data Privacy and Information Governance flashcards as text
Which U.S. federal law primarily governs the privacy of health information held by covered entities and their business associates?
Answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting sensitive patient health information.
Under the NIST Privacy Framework, which core function focuses on developing organizational understanding to manage privacy risk?
Answer: Identify-P
The Identify-P function in the NIST Privacy Framework helps organizations understand the privacy risks associated with data processing activities.
A data governance policy that defines who can access, modify, and delete data is best described as a:
Answer: Data access control policy
A data access control policy formally defines the rules governing who may access, alter, or remove organizational data assets.
Which concept requires organizations to collect only the minimum amount of personal data necessary for a stated purpose?
Answer: Data minimization
Data minimization is the principle of limiting personal data collection to what is directly relevant and necessary to accomplish a specified purpose.
The California Consumer Privacy Act (CCPA) grants California residents the right to:
Answer: Know what personal data is collected about them and request its deletion
CCPA gives California residents rights including knowing what personal data businesses collect, the right to delete it, and the right to opt out of its sale.
In information governance, a 'data owner' is best defined as:
Answer: The business unit accountable for the accuracy and use of a data set
A data owner is typically a senior business stakeholder who holds accountability for the integrity, security, and appropriate use of a specific data set.