RCC Data Privacy and Information Security Compliance Flashcards
6 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 RCC Data Privacy and Information Security Compliance flashcards as text
Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with:
Answer: Privacy notices explaining information sharing practices and an opt-out right
GLBA requires financial institutions to provide privacy notices that describe their information-sharing practices and allow consumers to opt out of sharing with non-affiliated third parties.
An organization's 'acceptable use policy' for information systems PRIMARILY serves to:
Answer: Establish rules for appropriate use of company technology and data resources
An acceptable use policy defines permissible and prohibited uses of organizational systems, networks, and data, forming a key component of the information security compliance framework.
What is the primary goal of 'data classification' in an information security compliance program?
Answer: To categorize data by sensitivity so appropriate protection controls can be applied
Data classification assigns sensitivity levels (e.g., public, internal, confidential, restricted) to data assets so that commensurate security and privacy controls can be applied based on the data's risk.
The Children's Online Privacy Protection Act (COPPA) requires operators of online services to obtain verifiable parental consent before collecting personal information from children under:
Answer: 13 years of age
COPPA applies to the online collection of personal information from children under 13 and requires verifiable parental consent before such collection occurs.
Which concept describes the idea that individuals should be able to access and correct their own personal information held by an organization?
Answer: Access and rectification rights
Access and rectification rights give individuals the ability to review the personal data held about them and request corrections to inaccurate or incomplete information.
An organization that retains personal data longer than necessary for its stated purpose is most likely violating which privacy principle?
Answer: Storage limitation
The storage limitation principle requires that personal data be kept for no longer than necessary for the purpose it was collected, after which it should be deleted or anonymized.