ISAC Data Protection and Privacy 3 — Questions and Answers
Question 1: Which ISO/IEC standard provides a framework specifically for information security management systems that cytometry labs can certify against to demonstrate data protection controls?
- ISO 15189
- ISO/IEC 27001 (Correct answer)
- ISO 9001
- ISO/IEC 29101
Correct answer: ISO/IEC 27001
ISO/IEC 27001 specifies requirements for establishing, implementing, and continually improving an Information Security Management System (ISMS).
Question 2: A biobank stores cytometry data alongside donor genetic profiles. Under the Common Rule (45 CFR 46), what additional protection applies to stored identifiable biospecimens used in future research?
- Mandatory de-identification before any secondary use
- IRB review and often re-consent for new research uses (Correct answer)
- Automatic exemption if data is older than five years
- Restriction to federal government researchers only
Correct answer: IRB review and often re-consent for new research uses
The revised Common Rule requires IRB review and, in many cases, broad consent or re-consent when identifiable biospecimens are used in secondary research.
Question 3: Which access control model is most appropriate for a multi-institutional cytometry network where data access should be determined by a user's job function rather than individual identity?
- Discretionary access control (DAC)
- Mandatory access control (MAC)
- Role-based access control (RBAC) (Correct answer)
- Attribute-based access control (ABAC)
Correct answer: Role-based access control (RBAC)
RBAC assigns permissions based on organizational roles, making it ideal for research networks where job function determines legitimate data needs.
Question 4: A GDPR data subject requests deletion of their cytometry data from a research cohort. Under which circumstance may the research institution legitimately refuse this request?
- The data is more than two years old
- Processing is necessary for public interest scientific research and erasure would seriously impair the research objective (Correct answer)
- The data has already been published in a journal
- The subject did not make the request in writing
Correct answer: Processing is necessary for public interest scientific research and erasure would seriously impair the research objective
GDPR Article 17(3)(d) allows refusal of erasure requests when processing is necessary for scientific research and erasure would seriously impair the research objective.
Question 5: Which encryption standard is currently recommended by NIST for protecting cytometry data at rest on laboratory storage systems?
- DES (56-bit)
- 3DES (112-bit)
- AES-256 (Correct answer)
- RC4
Correct answer: AES-256
NIST recommends AES-256 as the current standard for encrypting sensitive data at rest due to its security strength and widespread implementation.
Question 6: In cytometry research, 'pseudonymization' differs from 'anonymization' in that pseudonymized data:
- Can never be re-linked to individuals under any circumstances
- Can be re-linked to individuals using a separately held key (Correct answer)
- Is exempt from all GDPR requirements
- Requires no safeguards during transfer
Correct answer: Can be re-linked to individuals using a separately held key
Pseudonymized data replaces direct identifiers with a key but remains personal data under GDPR because re-identification is possible using that key.
Question 7: A cytometry researcher in the US collaborates with a European partner institution and transfers patient-linked FCS files to the EU. Which mechanism can legally facilitate this transfer under GDPR?
- A simple email encryption agreement
- Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- A unilateral privacy policy posted on the lab website
- Verbal agreement at an ISAC conference
Correct answer: Standard Contractual Clauses (SCCs) approved by the European Commission
Standard Contractual Clauses are pre-approved data transfer mechanisms under GDPR that can legitimize transfers of personal data to third countries lacking an adequacy decision.
Which ISO/IEC standard provides a framework specifically for information security management systems that cytometry labs can certify against to demonstrate data protection controls?