IGP Information Governance Framework & Policies 5 — Questions and Answers
Question 1: When an organization undergoes a merger, which IG activity is MOST urgent to perform regarding information assets?
- Immediately deleting all records from the acquired company
- Conducting an information inventory and gap analysis of both organizations' IG frameworks (Correct answer)
- Transferring all IT systems to the acquiring company's platform within 30 days
- Suspending all IG policies until the merger is complete
Correct answer: Conducting an information inventory and gap analysis of both organizations' IG frameworks
A merger requires an information inventory and gap analysis to identify IG framework differences, redundancies, and risks before integration decisions are made.
Question 2: Which of the following BEST describes 'information governance' as distinct from 'records management'?
- Information governance focuses only on physical documents while records management covers digital files
- Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance (Correct answer)
- Records management is a newer discipline that has replaced information governance
- Information governance is limited to legal and compliance departments
Correct answer: Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance
IG is a holistic, strategic discipline that encompasses records management and extends to include data governance, privacy, security, compliance, and risk management across all information assets.
Question 3: A Chief Information Governance Officer (CIGO) is MOST responsible for:
- Managing the organization's IT infrastructure and helpdesk
- Overseeing the enterprise IG program, ensuring alignment with strategy, and driving policy adoption across business units (Correct answer)
- Conducting financial audits of the IG department's budget
- Directly managing individual employee compliance with IT security policies
Correct answer: Overseeing the enterprise IG program, ensuring alignment with strategy, and driving policy adoption across business units
The CIGO provides strategic leadership for the enterprise IG program, aligning IG initiatives with organizational objectives and driving cross-functional adoption.
Question 4: Which of the following would be considered a 'defensible disposition' practice in IG?
- Randomly deleting files when storage is running low
- Destroying records according to documented retention schedules after confirming no legal holds apply (Correct answer)
- Retaining all records indefinitely to avoid any potential legal risk
- Allowing individual employees to decide when to delete their own emails
Correct answer: Destroying records according to documented retention schedules after confirming no legal holds apply
Defensible disposition requires systematic destruction based on approved retention schedules, with legal hold checks and documented authorization to withstand legal scrutiny.
Question 5: Under GDPR, which IG principle requires that personal data be kept only as long as necessary for its stated purpose?
- Data minimization
- Storage limitation (Correct answer)
- Purpose limitation
- Integrity and confidentiality
Correct answer: Storage limitation
GDPR's storage limitation principle requires that personal data not be kept longer than necessary for the purposes for which it was collected.
Question 6: An IG policy that applies to all employees, contractors, and vendors who access organizational information reflects which best practice?
- Limiting IG obligations to full-time employees only to reduce training costs
- Defining a broad scope that covers all parties who interact with organizational information regardless of employment status (Correct answer)
- Restricting IG requirements to data processed within the organization's primary country
- Applying separate, unconnected policies for each vendor individually
Correct answer: Defining a broad scope that covers all parties who interact with organizational information regardless of employment status
Effective IG policies must extend to all parties accessing organizational information — including contractors and vendors — since data risks are not limited to internal employees.
Question 7: Which approach BEST supports continuous improvement of an IG framework over time?
- Implementing a one-time IG audit with no follow-up
- Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions (Correct answer)
- Replacing the IG team annually to bring fresh perspectives
- Delegating all IG improvement decisions to an external consultant
Correct answer: Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions
Continuous improvement requires regular audits, monitoring of compliance metrics, and a formal feedback process to update policies as regulations, technology, and business needs evolve.
When an organization undergoes a merger, which IG activity is MOST urgent to perform regarding information assets?