IGP Information Governance Framework & Policies 3 — Questions and Answers
Question 1: Which of the following BEST describes the purpose of a data classification policy?
- To organize files into folders on a shared drive
- To assign sensitivity levels to information to guide handling and protection requirements (Correct answer)
- To set performance benchmarks for data processing systems
- To define the hierarchy of employees who can delete records
Correct answer: To assign sensitivity levels to information to guide handling and protection requirements
Data classification policies assign sensitivity tiers (e.g., Public, Internal, Confidential, Restricted) to information so appropriate controls can be applied.
Question 2: Which framework is commonly used to align IT governance with business objectives and includes information governance components?
- HIPAA
- COBIT (Correct answer)
- SOX
- FERPA
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is a framework for IT governance and management that includes information governance components.
Question 3: An information governance maturity model is primarily used to:
- Rank employees based on their IG knowledge
- Assess and benchmark the sophistication of an organization's IG program over time (Correct answer)
- Determine software licensing costs for records management tools
- Set quarterly sales goals for the compliance department
Correct answer: Assess and benchmark the sophistication of an organization's IG program over time
Maturity models provide a structured way to assess where an organization's IG program stands and chart a path for continuous improvement.
Question 4: Which scenario BEST illustrates a failure of IG policy enforcement?
- An employee requests access to a restricted database and is denied
- A manager approves deletion of records still under a legal hold (Correct answer)
- The IT team upgrades the records management system during off-hours
- Legal counsel reviews contracts before they are signed
Correct answer: A manager approves deletion of records still under a legal hold
Deleting records subject to a legal hold violates IG policy and can result in spoliation sanctions, making it a clear enforcement failure.
Question 5: The concept of 'information stewardship' in IG frameworks refers to:
- The CIO's authority to purchase information technology
- Designated individuals responsible for overseeing the quality and governance of specific data domains (Correct answer)
- The legal department's control over litigation records
- Automated software that classifies documents without human intervention
Correct answer: Designated individuals responsible for overseeing the quality and governance of specific data domains
Information stewards are accountable business representatives who oversee the accuracy, accessibility, and appropriate use of information within their domain.
Question 6: Which policy element defines the consequences for employees who violate IG requirements?
- Scope statement
- Enforcement and sanctions clause (Correct answer)
- Purpose and objectives section
- Glossary of terms
Correct answer: Enforcement and sanctions clause
The enforcement and sanctions clause specifies disciplinary actions that may result from policy violations, making the policy credible and actionable.
Question 7: A records retention schedule that conflicts with a legal hold should be:
- Applied as written since the schedule takes precedence
- Suspended for the records covered by the legal hold until it is lifted (Correct answer)
- Escalated to HR for employee discipline
- Deleted from the system to avoid confusion
Correct answer: Suspended for the records covered by the legal hold until it is lifted
Legal holds override normal retention schedules; records subject to a hold must be preserved until the hold is lifted, regardless of their scheduled destruction date.
Which of the following BEST describes the purpose of a data classification policy?