Information Management Flashcards
Operational Risks
Affects Efficiency
Ensure the privacy policy does not unnecessarily inhibit organizational needs and goals
May be a driver in privacy policy reform
Investment Risks
Hampering the ability of the organization to receive an appropriate return on its investments in information, IT
and information processing programs
Privacy Policy Steps
Discover
Build
Communicate
Evolve
Discover
Goals Inventory Classification Risks Data Flows Data Sharing Data Transfer Accountability Best Practices
Build
Privacy Policies
Privacy Notices
Communicate
Documentation
Training
Communication
Accountability
Evolve
Monitor
Revise
Adapt
double opt-in
requires the data subject to confirm their choice via a response to a follow-up email
Information the consumer should expect to be shared with third parties or used in other ways (e.g., third-party shipping, fraud prevention, first-party marketing)
No option
Data Retention Policy Advantages
Reduce risk of breach
Save money on storage limits
regulatory
Vendor Due Diligence
Reputation prior security incidents financial condition security controls point of transfer Disposal information employee training/awareness Vender Incident Response Audit rights third party security certifications