When contracting with a Software as a Service (SaaS) provider, which of the following is the MOST important contractual requirement to ensure data privacy at service termination?
Answer : B
When contracting with a SaaS provider, it is important to ensure that the provider will remove all customer data from their systems and storage devices at the end of the service contract. This will prevent any unauthorized access, use, or disclosure of the customer data by the provider or third parties after the service termination. Removal of customer data means that the data are permanently erased and cannot be recovered or restored by any means.
ISACA, Data Privacy Audit/Assurance Program, Control Objective 9: Data Disposal, p.16-171
ISACA, CDPSE Review Manual 2021, Chapter 4: Privacy Incident Response, Section 4.2: Data Disposal and Destruction, p. 151-152.
Which of the following is the BEST approach for an organization that wants to transfer risk associated with a potential breach involving customer personal data?
Answer : B
Risk transfer means shifting financial liability or impact to another party. Cyber insurance (B) directly achieves this by covering breach-related costs. Adopting standards (A) and retaining third parties (C, D) are risk mitigation/reduction, not transfer.
''Risk transfer is commonly achieved via insurance coverage for breach costs and liabilities.''
Which of the following BEST enables an IT privacy practitioner to ensure appropriate protection for personal data collected that is required to provide necessary services?
Answer : A
The best way for an IT privacy practitioner to ensure appropriate protection for personal data collected that is required to provide necessary services is to understand the data flows within the organization. Data flows are the paths or processes through which personal data moves within or outside the organization, from the point of collection to the point of disposal. Understanding the data flows helps to identify and analyze the privacy risks and impacts of data processing activities, such as data collection, storage, processing, sharing, and disposal. Understanding the data flows also helps to determine and apply the appropriate measures to protect personal data, such as data minimization, consent, access, rectification, erasure, portability, security, breach notification, etc. Understanding the data flows also helps to comply with the applicable privacy regulations and standards that govern data processing activities.Reference:: CDPSE Review Manual (Digital Version), page 97
Which of the following should be the FIRST consideration when selecting a data sanitization method?
Answer : D
The first consideration when selecting a data sanitization method is the type of storage device that holds the data to be sanitized. Different types of storage devices have different characteristics and limitations that affect the effectiveness and feasibility of data sanitization methods.For example, magnetic media, such as hard disk drives (HDDs), can be sanitized by data degaussing, which is wiping data permanently by weakening the magnetic field1.However, data degaussing is not applicable to devices that use solid state drive (SSD) technology, since SSDs do not store data magnetically2. Therefore, the storage type determines which data sanitization methods are suitable and available for the data disposal process.
ISACA, Why (and How to) Dispose of Digital Data, Data Degaussing1
ISACA, Best Practices for Data Hygiene, Data Hygiene Practices3
TechReset, Data Sanitization and Methods, Cryptographic Erasure2
Imperva, What is Data Sanitization?4
Which of the following scenarios poses the GREATEST risk to an organization from a privacy perspective?
Answer : A
The scenario that poses the greatest risk to an organization from a privacy perspective is that the organization lacks a hardware disposal policy. A hardware disposal policy is a policy that defines how the organization should dispose of or destroy hardware devices that contain or process personal data, such as laptops, servers, hard drives, USBs, etc. A hardware disposal policy should ensure that personal data is securely erased or overwritten before the hardware device is discarded, recycled, donated, or sold. A hardware disposal policy should also comply with the applicable privacy regulations and standards that govern data retention and destruction. By lacking a hardware disposal policy, the organization exposes personal data to potential threats, such as theft, loss, or unauthorized access, use, disclosure, or transfer.Reference:: CDPSE Review Manual (Digital Version), page 123
Which of the following MUST be available to facilitate a robust data breach management response?
Answer : D
To facilitate a robust data breach management response, an organization must have an inventory of affected individuals and systems, as this will help to identify the scope, impact and severity of the breach, and to take appropriate actions to contain, mitigate and notify the breach. An inventory of affected individuals and systems should include the following information:
The number and categories of data subjects whose personal data have been compromised
The types and volumes of personal data that have been exposed, altered or deleted
The sources and locations of the personal data, such as databases, servers, devices or third parties
The potential or actual consequences of the breach for the data subjects, such as identity theft, fraud, discrimination or physical harm
The systems and processes that have been compromised or affected by the breach, such as networks, applications, devices or security controls
The vulnerabilities or risks that have been exploited or introduced by the breach, such as malware, phishing, ransomware or human error
An inventory of affected individuals and systems will help the organization to assess the risk level of the breach, and to determine the appropriate response strategy and actions, such as:
Isolating or shutting down the affected systems or processes
Restoring or recovering the personal data from backups or other sources
Erasing or encrypting the personal data on the compromised devices or media
Analyzing the root cause and impact of the breach
Reporting the breach to the relevant authorities and stakeholders
Notifying the data subjects of their rights and remedies
Implementing corrective and preventive measures to avoid future breaches
Data Breach Preparation and Response in Accordance With GDPR - ISACA, section 4: ''The controller should document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.''
Cybersecurity Incident Response Exercise Guidance - ISACA, section 3: ''The IRT should identify all assets involved in an incident (e.g., hardware, software) and determine what information was compromised (e.g., PII).''
Guide to Securing Personal Data in Electronic Medium, section 3.5: ''Organisations should maintain an inventory of personal data in their possession or under their control.''
Which data warehousing operating model masks data within a larger database to provide subset views to users?
Answer : A