Chapter 9 Siedel Flashcards

1
Q

Katie is assessing her organizations privacy practices and determines that the organization previously collected customer addresses for the purpose of shipping goods and is now using those addresses to mail promotional materials. If this possibility was not previously disclosed, what privacy principle is the organization most likely violating?

A. Quality
B. Management
C. Notice
D. Security

A

C. Notice

Explanation:
One of the provisions of the notice principle is that organizations shoudl provide notice to data subjects before they use information for a purpose other than those that were previously disclosed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Kara is the chief privacy officer of an organization that maintains a database of customer information for marketing purposes. What term best describes the role of Kara’s organization with respect to that database?

A. Data subject
B. Data custodian
C. Data controller
D. Data processor

A

C. Data controller

Explanation:
Kara’s organization is collecting and processing this information for its own business needs. Therefore, it is best described as the data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Richard would like to use an industry standard reference for designing his organizations privacy controls. Which one of the following standards is best suited for this purpose?

A. ISO 27001
B. ISO 27002
C. ISO 27701
D. ISO 27702

A

C. ISO 27701

Explanation:
ISO 27701 covers best practices for implementing privacy controls. ISO 27001 and ISO 27002 relate to an organizations information security program. ISO 27702 does not yet exist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When designing privacy controls, an organization should be infomred by the results of what type of analysis?

A. Impact analysis
B. Gap analysis
C. Business analysis
D. Authorization analysis

A

B. Gap analysis

Explanation:
The gap anbalysis is the formal process of identifying deficiencies that prevent an organization from achieving its privacy objectives. The results of the gap analysis may be used to design new controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

State data breach notification laws may require organizations to notify which of the following parties?

A. Consumers impacted by the breach
B. State regulatory authorities
C. National credit reporting agencies
D. All of the above

A

D. All of the above

Explanation:
While they vary by state, breach notification laws may require notification to consumers, state regulators, and credit reporting agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following is not a potential consequence an organization may face under state law following a breach?

A. An obligation to provide free credit monitoring to affected consumers
B. Enforcement actions, including penalties, from state attorneys general
C. Civil actions brought by consumers udner a private right of action
D. Criminal prosecution of company employees who allowed the breach to occur

A

D. Criminal prosecution of compan employees who allowed the breach to occur

Explanation:
Whilke not all statets impose all of these penalties, free credit monitoring, penalties south by an attorney general, and civil cuits arising from a private right of action are potential consequences for an organizaton. Unless some other criminal act has occurred, criminal prosecution of employees is highly unlikely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

MediRecs Co provides secure server space to help healthcare providers store medical records. MediRecs would be best described under HIPAA as which of the following?

A. Service provider
B. Business Associate
C. Covered partner
D. Covered entity

A

B. Business Associate

Explanation:
Under HIPAA, business associates are third party firms that participate in the handling of PHI for a covered entity. Covered entities are required to have a business associate agreement (BAA) with such companies that confer responsibility for HIPAA compliance on the third party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Dimitri cashed a paycheck at County Bank three months ago, but he doesnt have an account there and hasnt been back since. Under GLBA, County Bank should consider Dimitri as which of the followiing?

A. Customer
B. Consumner
C. Visitor
D. No relationship with the bank

A

B. Consumner

Explanation:
GLBA distinguishes between customers and consumers. Customers are people like account holders who have ongoing relationships with the bank. COnsumers may only conduct isolated transactions with the bank. this is important because the bank has fewer obligations to Dimitri under GLBA because he is not technically a customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which amendment to the US Constitution explicitly grnats individuals the right to privacy?

A. First Amendment
B. Fourth Amendment
C. Fifth Amendment
D. None of the above

A

D. None of the above

Explanation:
The Fourth Amendment has been interpreted to provide indivuduals with some privacy rights, but it does not explicitly establish a right to privacy. The word privacy appears nowhere in the text of the constitution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What source contains much of the administrative law created by the US governemtn?

A. US Code
B. Bill of Rights
C. Code of Federal Regulations
D. US Constitution

A

C. Code of Federal Regulations

Explanation:
Administrative law is commonly documented in the Code of Federal Regulations. (CFR). The US Code contains legislative law. The US Constitution and its amendments (including the Bill of Rights) contain constitutional law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

During a negligence lawsuite, the court determined that the respondent was not at fault because the plaintiff did not present evidence that they suffered some for of harm. What element of negligence was missing from this case?

A. Duty of care
B. Breach of duty
C. Causation
D. Damages

A

D. Damages

Explanation:
In order to prevail on a negligence claim, the plaintiff must establish that there were damages involved, meaning that they suffiered some type of financial, physical, emotional or reputational harm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which of the following elements is not always required for the creation of a legal contract?

A. An offer
B. Acceptance of an offer
C. Written agreement
D. Consideration

A

C. Written agreement

Explanation:
Many states do have laws requiring that some contracts be in written form, but there is no universal requirement that a contractual agreement take place in writing, although written contracts are clearly preferable. The conditions that must be met for a contract to be enforceable include that each party to the contract must have the capacity to agree to the contract, an offer must be made by one party and accepted by the other, consideration must be given, and there must be mutual intent to be bound

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What category of law best describes the HIPAA Privacy Rule?

A. Constitutional Law
B. Common Law
C. Legislative Law
D. Administrative Law

A

D. Administrative Law

Explanation:
HIPAA is legislation passed by Congress. However, the HIPAA Privacy Rule and HIPAA Security Rule did not go through legislative process. They are examples of administrative law created by the Department of Health and Human Service to implement the requirements of HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which statute addresses security and privacy matters in the US financial industry?

A. GLBA
B. FERPA
C. SOX
D. HIPAA

A

A. GLBA

Explanation:
The Gramm Leach Biley Act governs the security and privacy of personal information in the financial industy. The Family Educational Rights and Privacy Act (FERPA) applies to educational institutions. The Sarbanes Oxley Act (SOX) governs the records of publicly traded corportations. HIPAA applies to healthcare providers, health insurers and health information clearinghouses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The right to be forgotten refers to which of the following?

A. The right to no longer pay taxes
B. Erasing criminal history
C. The right to have all of a data subjects data erased
D. Masking

A

C. The right to have all of a data subjects data erased

Explanation:
The right to be forgotten was first established under the European Unions General Data Protection Regulation (GDPR). It requires that, in many circumstances, companies delete personal information maintained about an individual at that individuals request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which one of the following organization is least likely to be subject to the requirements of HIPAA?

A. Health insurance company
B. Hospital
C. Medical device manufacturer
D. Health information clearinghouse

A

C. Medical device manufacturer

Explanation:
HIPAA applies to three types of covered entities: healthcare providers (such as doctor and hospitals), health insurers, and health information clearinghourses. Medical device manufacturers do not fit into any of these categories and are unlikely to handle the protect health information of individual patients

17
Q

Which one of the following options is no longer valid for protecting the transfer of personal information between the European Union and other nations?

A. Adequacy decisions
B. EU/US Privacy Shield
C. Binding Corporate Rules
D. Standard Contractual Clauses

A

B. EU/US Privacy Shield

Explanation:
Organizations may transfer information between the European Union and other nations when there is an adequacy decision in place that the laws of the other nation comply with GDPR. They may also choose to adopt Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)
They used to be able to transfer data under the safe harbor provisions of the EU US privacy shield, but this was struck down by the Schrems II decision

18
Q

Which one of the following is not a law that would concern cloud security professionals?

A. GLBA
B. HIPAA
C. PCI DSS
D. SOX

A

C. PCI DSS

Explanation:
All of these regulations would concern cloud security professionals. However, the PCI DSS is a private regulatory scheme, not a law

19
Q

What styandard governs SOC audits that occur within the United States?

A. SSAE 16
B. SSAE 18
C. ISAE 3402
D. ISAW 3602

A

B. SSAE 18

Explanation:
SOC audits performed in the United States are subject to SSAE 18. The earlier SSAE 16 standard for these audits is no longer relevant. The ISAE 3402 standard governs SOC audits outside of the US

20
Q

You are considering working with a cloud provider and would like to review the results of an audit that contains detailed information on security controls. The provider requirers that you sign an NDA before reviewing the material. What category of report are you likely reviewing?

A. SOC 1
B. SOC 2
C. SOC 3
D. SOC 4

A

B. SOC 2

Explanation:
SOC 2 reports contain information on an organizations security controls and include detailed sensitive information. They are not normally shared outside of an NDA. SOC 3 reports contain similar types of information but at a level suitable for public disclosure. SOC 1 reports are normally used as a component of a financial audit. SOC 4 reports do not exist

21
Q
A