Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Complete CIPM IAPP Materials

Page: 10 / 21
Total 274 questions

Certified Information Privacy Manager (CIPM) Questions and Answers

Question 37

You are the privacy operations lead at a mid-size multi-national business to business (B2B) technology organization. The privacy program is moderately mature and you are looking to enhance and expand training and awareness at all levels of the business. You want to launch an effort that helps bring privacy into focus for specific job families, categories and lines of the business (e.g., developers, program managers, architects) but your privacy team is small and you don't have a large budget to make this happen.

You set up a meeting with internal communications to identify possible awareness opportunities to meet these objectives and have secured spots at several upcoming all team meetings to present on privacy. Your goals are to establish an enterprise-wide privacy program awareness plan and toolkit involving various stakeholders that is then tailored to internal operational departments.

(Which of the following actions would help you best determine internal stakeholders to achieve your goals using a risk-based approach?)

Options:

A.

Ask supervisors to nominate a staffer to participate.

B.

Conduct small group sessions to identify and understand the relevant stakeholders.

C.

Post a message on your website asking for assistance with your privacy awareness plan.

D.

Send an enterprise-wide email to all employees asking for volunteers to help with awareness campaigns.

Question 38

Which item below best represents how a privacy group can effectively communicate with functional areas?

Options:

A.

Work independently and share the knowledge with functional groups.

B.

Work closely with functional areas by acting as both an advisor and an advocate.

C.

Choose a work unit representative and funnel all communications through that one person.

D.

Monitor the responsibilities of managers who are responsible for the privacy of functional areas.

Question 39

SCENARIO

Please use the following to answer the next QUESTION:

Your organization, the Chicago (U.S.)-based Society for Urban Greenspace, has used the same vendor to

operate all aspects of an online store for several years. As a small nonprofit, the Society cannot afford the higher-priced options, but you have been relatively satisfied with this budget vendor, Shopping Cart Saver (SCS). Yes, there have been some issues. Twice, people who purchased items from the store have had their credit card information used fraudulently subsequent to transactions on your site, but in neither case did the investigation reveal with certainty that the Society’s store had been hacked. The thefts could have been employee-related.

Just as disconcerting was an incident where the organization discovered that SCS had sold information it had collected from customers to third parties. However, as Jason Roland, your SCS account representative, points out, it took only a phone call from you to clarify expectations and the “misunderstanding” has not occurred again.

As an information-technology program manager with the Society, the role of the privacy professional is only one of many you play. In all matters, however, you must consider the financial bottom line. While these problems with privacy protection have been significant, the additional revenues of sales of items such as shirts and coffee cups from the store have been significant. The Society’s operating budget is slim, and all sources of revenue are essential.

Now a new challenge has arisen. Jason called to say that starting in two weeks, the customer data from the store would now be stored on a data cloud. “The good news,” he says, “is that we have found a low-cost provider in Finland, where the data would also be held. So, while there may be a small charge to pass through to you, it won’t be exorbitant, especially considering the advantages of a cloud.”

Lately, you have been hearing about cloud computing and you know it’s fast becoming the new paradigm for various applications. However, you have heard mixed reviews about the potential impacts on privacy protection. You begin to research and discover that a number of the leading cloud service providers have signed a letter of intent to work together on shared conventions and technologies for privacy protection. You make a note to find out if Jason’s Finnish provider is signing on.

What process can best answer your Questions about the vendor’s data security safeguards?

Options:

A.

A second-party of supplier audit

B.

A reference check with other clients

C.

A table top demonstration of a potential threat

D.

A public records search for earlier legal violations

Question 40

The main reason the response to this incident should be integrated into the Business Continuity Plan (BCP) is because?

Options:

A.

The repercussions for the company could have significant environmental impacts.

B.

The need for retraining employees will be paramount.

C.

Major stakeholders are involved from every critical area of the business.

D.

The impact on the company's competitive advantage is potentially significant.

Page: 10 / 21
Total 274 questions