nerdexam
(ISC)2

CGRC · Question #104

An analysis of how information is handled: 1) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; 2) to determine the risks and effects of collectin

The correct answer is A. Privacy Impact Assessment (PIA). The described analysis process, focused on evaluating privacy risks and compliance for identifiable information handling, is known as a Privacy Impact Assessment (PIA).

Security and Privacy Governance, Risk Management, and Compliance Program

Question

An analysis of how information is handled: 1) to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; 2) to determine the risks and effects of collecting, maintaining, and disseminating information in identifiable form in an electronic information system; and 3) to examine and evaluate protections and alternative processes for handling information to mitigate potential privacy risks. Response:

Options

  • APrivacy Impact Assessment (PIA)
  • BCore Nodal Switching Subsystem (CNSS)
  • CIndustry Standard Architecture (ISA)
  • DPersonally Identifiable Information (PII)

How the community answered

(56 responses)
  • A
    88% (49)
  • B
    2% (1)
  • C
    7% (4)
  • D
    4% (2)

Why each option

The described analysis process, focused on evaluating privacy risks and compliance for identifiable information handling, is known as a Privacy Impact Assessment (PIA).

APrivacy Impact Assessment (PIA)Correct

A Privacy Impact Assessment (PIA) is a structured process to identify and assess the privacy risks associated with the collection, use, maintenance, and dissemination of Personally Identifiable Information (PII) in an information system. It ensures adherence to privacy regulations and policies and helps mitigate potential privacy risks.

BCore Nodal Switching Subsystem (CNSS)

Core Nodal Switching Subsystem (CNSS) is an acronym not directly related to privacy assessments; it often refers to national security systems or directives.

CIndustry Standard Architecture (ISA)

Industry Standard Architecture (ISA) refers to an old computer bus standard and has no relevance to privacy impact analysis.

DPersonally Identifiable Information (PII)

Personally Identifiable Information (PII) is the type of information that a PIA assesses, but PII itself is not the assessment process.

Concept tested: Privacy Impact Assessment (PIA) definition.

Source: https://csrc.nist.gov/glossary/term/privacy-impact-assessment

Topics

#Privacy Impact Assessment (PIA)#Privacy Risk Management#Information Handling#Compliance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice