IV - Process Oriented Strategies Flashcards

1
Q

Supply (informing the individual)

A

Users should be informed of what information is being processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Notify (informing the individual)

A

users should be notified if their personal data has been exposed in a breach, or when they intend to use the data for a new purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain (informing the individual)

A

Privacy notices should clearly explain why the data collection is necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Consent (user control)

A

The org only processes information that has been freely given based on explicit and informed consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Choice (user control)

A

The org allows the individual to select or exclude the personal information that can be processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Update (user control)

A

The org provides a means by which the individual can keep their personal information accurate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Retract (user control)

A

The org honours the individuals right to have any personal information removed in a timely manner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Create (process and policy enforcement)

A

Org should create a privacy policy that describes how they’ll manage and protect personal information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Maintain (process and policy enforcement)

A

Orgs should maintain established policies and processes to ensure consistency of privacy practices throughout the org.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Uphold (process and policy enforcement)

A

Orgs should treat personal information as an asset and privacy as a primary goal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Log (demonstrate compliance)

A

Track all processing of data and review the logs for anything that might present a risk. Any deviations from standard processing procedures should be logged.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Audit (demonstrate compliance)

A

Audit logs to ensure that both logging and organizational activities are following established processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Report (demonstrate compliance)

A

Periodically create reports on tests, audits and logs and provide feedback to individuals responsible for those processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly