RCC RCC Data Privacy and Information Security Compliance 2 — Questions and Answers
Question 1: Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with:
- A list of all employees who can access their accounts
- Privacy notices explaining information sharing practices and an opt-out right (Correct answer)
- Free credit monitoring services annually
- Insurance guarantees for all financial losses
Correct answer: Privacy notices explaining information sharing practices and an opt-out right
GLBA requires financial institutions to provide privacy notices that describe their information-sharing practices and allow consumers to opt out of sharing with non-affiliated third parties.
Question 2: An organization's 'acceptable use policy' for information systems PRIMARILY serves to:
- Define employee compensation for IT-related work
- Establish rules for appropriate use of company technology and data resources (Correct answer)
- Restrict the IT department's ability to monitor systems
- Satisfy OSHA workplace safety requirements
Correct answer: Establish rules for appropriate use of company technology and data resources
An acceptable use policy defines permissible and prohibited uses of organizational systems, networks, and data, forming a key component of the information security compliance framework.
Question 3: What is the primary goal of 'data classification' in an information security compliance program?
- To organize data alphabetically for easy retrieval
- To categorize data by sensitivity so appropriate protection controls can be applied (Correct answer)
- To reduce the amount of data stored by the organization
- To comply with IRS record-keeping requirements
Correct answer: To categorize data by sensitivity so appropriate protection controls can be applied
Data classification assigns sensitivity levels (e.g., public, internal, confidential, restricted) to data assets so that commensurate security and privacy controls can be applied based on the data's risk.
Question 4: The Children's Online Privacy Protection Act (COPPA) requires operators of online services to obtain verifiable parental consent before collecting personal information from children under:
- 16 years of age
- 13 years of age (Correct answer)
- 18 years of age
- 10 years of age
Correct answer: 13 years of age
COPPA applies to the online collection of personal information from children under 13 and requires verifiable parental consent before such collection occurs.
Question 5: Which concept describes the idea that individuals should be able to access and correct their own personal information held by an organization?
- Data portability
- Access and rectification rights (Correct answer)
- Right to be forgotten
- Data residency
Correct answer: Access and rectification rights
Access and rectification rights give individuals the ability to review the personal data held about them and request corrections to inaccurate or incomplete information.
Question 6: An organization that retains personal data longer than necessary for its stated purpose is most likely violating which privacy principle?
- Data accuracy
- Storage limitation (Correct answer)
- Transparency
- Purpose specification
Correct answer: Storage limitation
The storage limitation principle requires that personal data be kept for no longer than necessary for the purpose it was collected, after which it should be deleted or anonymized.
Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with: