Which of the following would best enhance an organization's system for limiting data use?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Why would you recommend that GFC use record-level encryption rather than disk, file, or table encryption?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
When publishing aggregates, what must be done to magnitude data to preserve privacy?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
What tactic does pharming employ to accomplish its objective?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
If Clean-Q uses LeadOps’ services, which contract clause may be included in the agreement with LeadOps?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Which biometric type is the most accurate?
Community Discussion
No comments yet. Be the first to start the discussion!
SCENARIO —
Reflecting on your first two years as Director of Personal Information Protection and Compliance for Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a series of accomplishments—from developing state-of-the-art simulation-based privacy-protection training for employees to establishing an interactive medical-records system accessible to patients as well as medical personnel. However, a question you have deferred now looms large: how should all the data be managed—not only recently created records, but also those retained from years ago? A data-flow diagram produced last year shows multiple servers, databases, and workstations, many holding files that have not yet been incorporated into the new records system. Although most of this data is encrypted, retaining it may create security and compliance concerns. The situation is further complicated by several long-term studies conducted by medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to ensure that the medical center complies with them.
You also remember a recent visit to the Records Storage Section—often called The Dungeon—in the basement of the old hospital beside the modern facility, where you observed a multitude of paper records. Some were in crates marked by year, medical condition, or patient name alphabetically, while others were in unclassified bundles on shelves and the floor. The section’s rear shelves held data tapes and old hard drives that were frequently unlabeled but appeared to be years old. As you left the dungeon, you saw ahead of you a small man in a lab coat whom you did not recognize. He was carrying a batch of folders under his arm, apparently records he had removed from storage.
Which regulation is most likely to apply to the data stored by Berry Country Regional Medical Center?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
What is the primary privacy risk presented by Radio Frequency Identification (RFID)?
Community Discussion
No comments yet. Be the first to start the discussion!
SCENARIO –
Clean-Q is a company that provides household and office cleaning services. The company receives consumer requests via its website and telephone to book cleaning services. Based on the service type and size, Clean-Q contracts individuals registered on its resource database, which is currently managed internally by Clean-Q IT Support. Due to Clean-Q’s business model, resources are contracted as needed rather than employed permanently.
The table below identifies some of the personal information Clean-Q requires for its business operations:
Clean-Q has an internal employee base of about 30 people. A recent privacy-compliance exercise was carried out to align employee-data management and human-resources functions with applicable data-protection regulation. Therefore, Clean-Q’s permanent employee base is not included in this scenario.
With increased construction work and housing developments, Clean-Q has received an influx of requests for cleaning services. The demand has overwhelmed Clean-Q’s traditional supply-and-demand system, causing some overlapping bookings.
During a recent business-strategy session, senior management invited vendors to present potential solutions to their current operational issues. These vendors included application developers and cloud-solution providers, who presented their proposed solutions and platforms.
The Managing Director decided to begin integrating Clean-Q’s operations with a cloud solution, LeadOps, that will provide the following through one single online platform:
A web interface accessed by Clean-Q for resource and customer management, which would involve uploading resource and customer information.
A customer-facing web interface enabling customers to register, manage, and submit cleaning-service requests online.
A resource-facing web interface enabling resources to apply for and manage their assigned jobs.
An online payment facility for customers to pay for services.
Which question would you most likely ask to gain further insight about LeadOps and provide practical privacy recommendations?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Which term refers to two re-identifiable datasets that both originate from the same unidentified individual?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Which of the following represents a vulnerability in a sensitive biometric authentication system?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Users of a web-based email service have their accounts compromised through breached login credentials. Which potential outcomes of the breach demonstrate the two categories of Calo’s Harm Dimensions?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Value Sensitive Design (VSD) concentrates on which of the following?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
A privacy engineer is asked to review an online account login page. He discovers that users can make an unlimited number of invalid login attempts when accessing their online accounts.
What is the best recommendation to minimize the potential privacy risk created by this weakness?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
To prevent other people from identifying an individual in a data set, privacy engineers use a cryptographically secure hashing algorithm. Using hashes this way demonstrates which privacy tactic?
Community Discussion
No comments yet. Be the first to start the discussion!
A California, USA-based organization is implementing a new online helpdesk solution to record customer call information. The organization regards the collection of personal data through the online helpdesk solution as being in the company’s interest for providing the best service for customer calls.
Before implementation, which of the following should a privacy technologist conduct?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Which IT architecture would be most suitable for this mobile platform?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Which activity is typically not carried out by sophisticated Access Management (AM) techniques?
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
With respect to the app, which action exemplifies a decisional-interference violation?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion