IGP Compliance & Risk Management 4 — Questions and Answers
Question 1: A 'heat map' in risk management visually plots risks according to:
- Cost of mitigation vs. regulatory requirement
- Likelihood and potential impact (Correct answer)
- Data sensitivity vs. retention period
- Threat actor sophistication vs. asset value
Correct answer: Likelihood and potential impact
A risk heat map plots risks on a two-axis grid of likelihood (probability) and impact (severity) to prioritize response.
Question 2: HIPAA's Minimum Necessary Standard requires covered entities to:
- Encrypt all PHI at rest and in transit
- Limit PHI access and disclosure to the minimum needed for the intended purpose (Correct answer)
- Obtain written consent before any PHI disclosure
- Retain medical records for a minimum of 10 years
Correct answer: Limit PHI access and disclosure to the minimum needed for the intended purpose
The Minimum Necessary Standard limits access to and use of PHI to only what is needed to accomplish the intended purpose.
Question 3: Which of the following best describes a Key Risk Indicator (KRI)?
- A metric that measures compliance with a specific regulation
- A forward-looking metric that signals increasing risk exposure (Correct answer)
- A historical log of past risk events and their outcomes
- A financial ratio used to assess vendor creditworthiness
Correct answer: A forward-looking metric that signals increasing risk exposure
KRIs are predictive metrics that provide early warning signals of increasing risk before an adverse event occurs.
Question 4: Under FTC regulations, a company's privacy policy that makes false or misleading claims about data practices could result in enforcement action for:
- Patent infringement
- Unfair or deceptive acts or practices (UDAP) (Correct answer)
- Securities fraud
- RICO violations
Correct answer: Unfair or deceptive acts or practices (UDAP)
The FTC enforces Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, including misleading privacy representations.
Question 5: An organization decides not to pursue a new business opportunity because the associated data privacy risks are too high. This is an example of:
- Risk mitigation
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance means choosing not to engage in an activity because its risks outweigh the benefits.
Question 6: Which component of a compliance program is responsible for receiving and investigating reports of policy violations without fear of retaliation?
- Data stewardship committee
- Whistleblower or hotline program (Correct answer)
- Legal hold management
- Records retention schedule
Correct answer: Whistleblower or hotline program
A whistleblower or ethics hotline program provides a confidential channel for employees to report misconduct without fear of retaliation.
Question 7: The process of formally accepting a residual risk that cannot be further reduced is known as:
- Risk remediation
- Risk tolerance setting
- Risk acceptance (Correct answer)
- Risk acknowledgment
Correct answer: Risk acceptance
Risk acceptance is the formal decision to acknowledge a risk and take no further action, typically when the cost of controls exceeds the potential loss.
A 'heat map' in risk management visually plots risks according to: