CH 2 Managing Data Flashcards

1
Q

Under the General Data Protection Regulation (GDPR), a data controller’s role is to

A

Define how and for what purpose personal data should be processed.
The GDPR specifically defines the tasks of the data controller, a mark of the importance the European Union places on the personal privacy of its citizens.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internal data entry processes that capture accounting transactions, customer data or other operational transactions are called

A

Data capture.

Data capture, including data preparation, are a business’ day to day transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which one of the following is a data governance committee (DGC) responsibility?

A

A data governance committee ensures there are few conflicts or redundancies in data standards and practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In terms of data governance, IT employees hold the role of

A

Data custodians.
IT employees, including architects, are charged with managing the flow of data for an organization. This contrasts with role of a data steward who develop business rules based on the data model IT employees develop.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The data quality principle of reasonability refers to

A

The materiality or relevance of data.
Reasonability refers to both materiality and relevance of data, testing whether the information provided is pertinent to the business objective at hand.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which one of the following is true regarding data quality?

A

Data quality is a relative, not an absolute, concept.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

To gain a competitive advantage, maintain profitability, and satisfy customers an organization must

A

Be able to trust its data.
Organizations must be able to trust its data to be able to act on it in ways that are consistent with its holistic risk management strategy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which one of the following statements is correct regarding the personal data and privacy positions of the European Union (EU) and the U.S.?

A

The EU has one all-encompassing data protection framework and the U.S. has several more targeted privacy laws. The EU has a stronger cultural expectation of privacy that the U.S.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which one of the following is a basic process in any data security program?

A

Develop and enforce stronger password protocols. Developing and enforcing stronger password protocols is a critical first step in protecting a business’ data from unwanted intrusions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The lifeblood of every organizational function is

A

Data.
The first sentence of this section states the importance data carries for every organizational function and risk management decision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

There are two types of associated risk for data privacy, individual and general risk. General data privacy risk

A

Can be categorized operational or reputational.
A general data privacy risk is considered less specific than an individual risk. General data privacy risks concern a loss of reputation or safeguarding trade secrets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which one of the following functions of a data management program would allow accounting transactions to automatically update an organization’s financial statements?

A

Data integration.
Data integration is a function of a data management program that would allow accounting transactions to automatically update an organization’s financial statements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A privacy impact assessment (PIA) is

A

A tool used to identify and assess privacy risks.
A privacy impact assessment (PIA) can identify and assess privacy risks as well as identify whether information collected complies with legal and regulatory privacy requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In terms of data quality principles, validity is defined as

A

The accuracy of data within predefined and accepted parameters or values. Validity is defined as the accuracy of data within predefined and accepted parameters or values. Accuracy measures the true value of data relative to the true value of data relative to the business information being analyzed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which one of the following is an example of a data governance tool?

A

External Policy.
Data governance is more than just physical tools or software applications. A data governance committee also uses internal policies, external policies, enterprise data models and collaborative tools such as agile project management to achieve its aims.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Sound risk management decisions are predicated on

A

Quality data.
Quality data is critical to making sound risk management decisions. For example, up-to-date financial data may influence whether an organization decides to expand its product offerings.

17
Q

Which one of the following is an element of a data security program?

A

Storing data back-ups off site.
While working with data is critical to business success, securing that data is just as important. One element of protecting data is storing back-ups of key databases off site.

18
Q

Which one of the following defines individual risk?

A

Individual risk varies according to the type of business.

19
Q

Malware is defined as

A

Software designed to cause damage.

Malware is any software that is designed specifically to cause harm or damage to a computer, server, or network.

20
Q

Wycliffe Insurance is very concerned about data quality and has many safeguards in place to ensure the data it collects and stores is managed appropriately. New claims data is entered with the date of its arrival to the department. Then the claims representative’s activities are also entered with the date and time whenever the file is updated. The organization has chosen this data formatting to reflect the required degree of accuracy that has proven many times to be beneficial when the data is used in settlement negotiations or arbitration hearings. The dimension of stored data quality used in this case by Wycliffe is

A

Precision.

The dimension of stored data quality used in this case is precision.

21
Q

Data governance provides

A

Definitions, standards and procedures for how data is used.

Data governance is the starting point, or rule set for managing data.