<< Prev Question Next Question >>

Question 3/31

SCENARIO
Please use the following to answer the next question:
As the director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomplishments so far. Your hiring was precipitated by warnings from regulatory agencies following a series of relatively minor data breaches that could easily have been worse. However, you have not had a reportable incident for the three years that you have been with the company. In fact, you consider your program a model that others in the data storage industry may note in their own program development.
You started the program at Consolidated from a jumbled mix of policies and procedures and worked toward coherence across departments and throughout operations. You were aided along the way by the program's sponsor, the vice president of operations, as well as by a Privacy Team that started from a clear understanding of the need for change.
Initially, your work was greeted with little confidence or enthusiasm by the company's "old guard" among both the executive team and frontline personnel working with data and interfacing with clients. Through the use of metrics that showed the costs not only of the breaches that had occurred, but also projections of the costs that easily could occur given the current state of operations, you soon had the leaders and key decision-makers largely on your side. Many of the other employees were more resistant, but face-to-face meetings with each department and the development of a baseline privacy training program achieved sufficient
"buy-in" to begin putting the proper procedures into place.
Now, privacy protection is an accepted component of all current operations involving personal or protected data and must be part of the end product of any process of technological development. While your approach is not systematic, it is fairly effective.
You are left contemplating: What must be done to maintain the program and develop it beyond just a data breach prevention program? How can you build on your success? What are the next action steps?
What analytic can be used to track the financial viability of the program as it develops?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (31q)
Question 1: An organization's privacy officer was just notified by the b...
Question 2: What is one reason the European Union has enacted more compr...
Question 3: SCENARIO Please use the following to answer the next questio...
Question 4: SCENARIO Please use the following to answer the next questio...
Question 5: Under the General Data Protection Regulation (GDPR), which o...
Question 6: SCENARIO Please use the following to answer the next questio...
Question 7: SCENARIO Please use the following to answer the next questio...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: The General Data Protection Regulation (GDPR) specifies fine...
Question 10: All of the following changes will likely trigger a data inve...
Question 11: SCENARIO Please use the following to answer the next questio...
Question 12: "Collection," "access" and "destruction" are aspects of what...
Question 13: What are you doing if you succumb to "overgeneralization" wh...
Question 14: In addition to regulatory requirements and business practice...
Question 15: SCENARIO Please use the following to answer the next questio...
Question 16: How are individual program needs and specific organizational...
Question 17: Which term describes a piece of personal data that alone may...
Question 18: SCENARIO Please use the following to answer the next questio...
Question 19: SCENARIO Please use the following to answer the next questio...
Question 20: Which statement is FALSE regarding the use of technical secu...
1 commentQuestion 21: SCENARIO Please use the following to answer the next questio...
Question 22: SCENARIO Please use the following to answer the next questio...
Question 23: If an organization maintains a separate ethics office, to wh...
Question 24: SCENARIO Please use the following to answer the next questio...
Question 25: An organization is establishing a mission statement for its ...
Question 26: Under the General Data Protection Regulation (GDPR), which s...
Question 27: SCENARIO Please use the following to answer the next questio...
Question 28: SCENARIO Please use the following to answer the next questio...
Question 29: SCENARIO Please use the following to answer the next questio...
Question 30: SCENARIO Please use the following to answer the next questio...
Question 31: Which is NOT an influence on the privacy environment externa...