6. Protect: Policies Flashcards

1
Q

Privacy Policy vs Privacy Notice

A

Privacy Policy - an internal document addressed to employees that clearly states how the organization handles personal information.

Privacy Notice- an external communication to data subjects

“Privacy Policy - should be clear and easy to understand, accessible to all employees, comprehensive yet concise, action-oriented, measurable, and testable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Types of Privacy Policies and Goals of Info Sec Policies (PPPP)

A

Types of Privacy Policies:
- Acceptable Use
- Info Sec
- Procurement
- HR
- Data Retention

Goals of Info Sec Policies:
- Protect against unauthorized access
- provide stakeholder information
- promote compliance
- promote data quality

Vendors should be held to the same standards as the organization they serve.
Cloud Computing Services Vendors - pose distinct privacy challenges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Policies of High Risk Areas

A

HR - handles diverse employee PII and typically has policies to guide processing.

Data Retention Policies - should support the idea that personal information should only be retain for as long as necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data retention

A

Determine what data is being retained, how and where stored

Understand legal requirements for data

Brainstorm scenarios that would require data retention

Estimate business impacts of retaining vs storing data

Develop and implement a policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Procurement: “Vendor Policy”

A

Identify vendors and their legal obligations

Evaluate risk, policies and server location

Develop a thorough contract

Monitor vendors practices and performance

Use a vendor policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly