<< Prev Question Next Question >>

Question 13/48

SCENARIO
Please use the following to answer the next QUESTION:
For 15 years, Albert has worked at Treasure Box - a mail order company in the United States (U.S.) that used to sell decorative candles around the world, but has recently decided to limit its shipments to customers in the
48 contiguous states. Despite his years of experience, Albert is often overlooked for managerial positions. His frustration about not being promoted, coupled with his recent interest in issues of privacy protection, have motivated Albert to be an agent of positive change.
He will soon interview for a newly advertised position, and during the interview, Albert plans on making executives aware of lapses in the company's privacy program. He feels certain he will be rewarded with a promotion for preventing negative consequences resulting from the company's outdated policies and procedures.
For example, Albert has learned about the AICPA (American Institute of Certified Public Accountans)/CICA (Canadian Institute of Chartered Accountants) Privacy Maturity Model (PMM). Albert thinks the model is a useful way to measure Treasure Box's ability to protect personal data. Albert has noticed that Treasure Box fails to meet the requirements of the highest level of maturity of this model; at his interview, Albert will pledge to assist the company with meeting this level in order to provide customers with the most rigorous security available.
Albert does want to show a positive outlook during his interview. He intends to praise the company's commitment to the security of customer and employee personal data against external threats. However, Albert worries about the high turnover rate within the company, particularly in the area of direct phone marketing. He sees many unfamiliar faces every day who are hired to do the marketing, and he often hears complaints in the lunch room regarding long hours and low pay, as well as what seems to be flagrant disregard for company procedures.
In addition, Treasure Box has had two recent security incidents. The company has responded to the incidents with internal audits and updates to security safeguards. However, profits still seem to be affected and anecdotal evidence indicates that many people still harbor mistrust. Albert wants to help the company recover.
He knows there is at least one incident the public in unaware of, although Albert does not know the details. He believes the company's insistence on keeping the incident a secret could be a further detriment to its reputation. One further way that Albert wants to help Treasure Box regain its stature is by creating a toll-free number for customers, as well as a more efficient procedure for responding to customer concerns by postal mail.
In addition to his suggestions for improvement, Albert believes that his knowledge of the company's recent business maneuvers will also impress the interviewers. For example, Albert is aware of the company's intention to acquire a medical supply company in the coming weeks.
With his forward thinking, Albert hopes to convince the managers who will be interviewing him that he is right for the job.
On which of the following topics does Albert most likely need additional knowledge?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (48q)
Question 1: SCENARIO Please use the following to answer the next QUESTIO...
Question 2: Which of the following is TRUE about a PIA (Privacy Impact A...
Question 3: In which situation would a Privacy Impact Assessment (PIA) b...
Question 4: A Human Resources director at a company reported that a lapt...
Question 5: SCENARIO Please use the following to answer the next QUESTIO...
Question 6: An executive for a multinational online retail company in th...
Question 7: Under which circumstances would people who work in human res...
Question 8: SCENARIO Please use the following to answer the next QUESTIO...
Question 9: SCENARIO Please use the following to answer the next QUESTIO...
Question 10: SCENARIO Please use the following to answer the next QUESTIO...
Question 11: What is the main reason to begin with 3-5 key metrics during...
Question 12: SCENARIO Please use the following to answer the next QUESTIO...
Question 13: SCENARIO Please use the following to answer the next QUESTIO...
Question 14: Why were the nongovernmental privacy organizations, Electron...
Question 15: SCENARIO Please use the following to answer the next QUESTIO...
Question 16: Rationalizing requirements in order to comply with the vario...
Question 17: Which of the following is NOT typically a function of a Priv...
Question 18: SCENARIO Please use the following to answer the next QUESTIO...
Question 19: SCENARIO Please use the following to answer the next QUESTIO...
Question 20: SCENARIO Please use the following to answer the next QUESTIO...
Question 21: Which of the following indicates you have developed the righ...
Question 22: What is one reason the European Union has enacted more compr...
Question 23: SCENARIO Please use the following to answer the next QUESTIO...
Question 24: SCENARIO Please use the following to answer the next QUESTIO...
Question 25: Which is the best way to view an organization's privacy fram...
Question 26: Which is NOT an influence on the privacy environment externa...
Question 27: SCENARIO Please use the following to answer the next QUESTIO...
Question 28: SCENARIO Please use the following to answer the next QUESTIO...
Question 29: SCENARIO Please use the following to answer the next QUESTIO...
Question 30: As a Data Protection Officer, one of your roles entails moni...
Question 31: SCENARIO Please use the following to answer the next QUESTIO...
Question 32: What is the main purpose of a privacy program audit?...
Question 33: SCENARIO Please use the following to answer the next QUESTIO...
Question 34: What is the function of the privacy operational life cycle?...
Question 35: SCENARIO Please use the following to answer the next QUESTIO...
Question 36: All of the following changes will likely trigger a data inve...
Question 37: SCENARIO Please use the following to answer the next QUESTIO...
Question 38: SCENARIO Please use the following to answer the next QUESTIO...
Question 39: SCENARIO Please use the following to answer the next QUESTIO...
Question 40: SCENARIO Please use the following to answer the next QUESTIO...
Question 41: Which of the following is an example of Privacy by Design (P...
Question 42: SCENARIO Please use the following to answer the next QUESTIO...
Question 43: Which of the following controls does the PCI DSS framework N...
Question 44: SCENARIO Please use the following to answer the next QUESTIO...
Question 45: Which is TRUE about the scope and authority of data protecti...
Question 46: Under the General Data Protection Regulation (GDPR), which s...
Question 47: Which of the following is TRUE about the Data Protection Imp...
Question 48: SCENARIO Please use the following to answer the next QUESTIO...