Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

DSCI DCPLA - DSCI Certified Privacy Lead Assessor

Page: 2 / 3
Total 86 questions

Which of the following mechanisms or steps is/are likely to be taken by an organization for implementing a privacy program?

i. Deploying physical and technology safeguards to protect personal information assets

ii. Privacy consideration in product and service design

iii. Privacy implementation to focus only on projects impacted by privacy breaches

iv. Benchmarking against industry peers' privacy implementation

v. Installing privacy enhancing tools and technologies for the projects dealing with organization's Intellectual Property

A.

i, ii, iii and iv

B.

All except iii

C.

Only i and ii

D.

Only i, ii and iv

Categorise the following statement:

"In case of eventualities or incidents, the organization struggles to locate source, evaluate reasons and fix the accountability."

A.

Visibility

B.

Capability

C.

Enforcement

D.

Demonstration

Which of the following could be considered as triggers for updating privacy policy? (Choose all that apply.)

A.

Regulatory changes

B.

Privacy breach

C.

Change in service provider for an established business process

D.

Recruitment of more employees

Entities should collect personal information from user that is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. This Privacy Principle is called:

A.

Collection Limitation

B.

Use Limitation

C.

Accountability

D.

Storage Limitation

Categorize the following statement:

“The network is unable to restrict unwanted external connections carrying sensitive information.”

A.

Visibility

B.

Capability

C.

Enforcement

D.

Demonstration

Which of the following factors is least likely to be considered while implementing or augmenting data security solution for privacy protection?

A.

Security controls deployment at the database level

B.

Information security infrastructure up-gradation in the organization

C.

Classification of data type and its usage by various functions in the organization

D.

Training and awareness program for third party organizations

The assessor organization can issue the DSCI certification to the assessee organization if it is satisfied with the assessment outcome.

A.

True

B.

False

FILL BLANK

PIS

The company has a well-defined and effectively implemented security policy. As in case of access control, the security controls vary in different client relationships based on the client requirements but certain basic or hygiene security practices / controls are implemented organization wide. The consultants have advised the information security function to realign the company’s security policy, risk assessment, data classification, etc to include privacy aspects. But the consultants are struggling to make information security function understand what exact changes need to be made and the security function itself is unable to figure it out.

(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a definitive conclusion)

Introduction and Background

XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom among others in Americas, Europe, Asia-Pacific, Middle East and Africa. The company provides IT services including application development and maintenance, IT Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI customers.

The company is witnessing phenomenal growth in the BPM services over last few years including FinanceandAccounting including credit card processing, Payroll processing, Customer support, Legal Process Outsourcing, among others and has rolled out platform based services. Most of the company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the company is looking to expand its operations in Europe. India, too has attracted company’s attention given the phenomenal increase in domestic IT spend esp. by the government through various large scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong focus on delivery of cloud services. When it comes to expanding operations in Europe, company is facing difficulties in realizing the full potential of the market because of privacy related concerns of the clients arising from the stringent regulatory requirements based on EU General Data Protection Regulation (EU GDPR).

To get better access to this market, the company decided to invest in privacy, so that it is able to provide increased assurance to potential clients in the EU and this will also benefit its US operations because privacy concerns are also on rise in the US. It will also help company leverage outsourcing opportunities in the Healthcare sector in the US which would involve protection of sensitive medical records of the US citizens. The company believes that privacy will also be a key differentiator in the cloud business going forward. In short, privacy was taken up as a strategic initiative in the company in early 2011.

Since XYZ had an internal consulting arm, it assigned the responsibility of designing and implementing an enterprise wide privacy program to the consulting arm. The consulting arm had very good expertise in information security consulting but had limited expertise in the privacy domain. The project was to be driven by CIO's office, in close consultation with the Corporate Information Security and Legal functions.

Can you please guide the information security function to realign company’s security initiatives to include privacy protection, keeping in mind that the client security requirements would vary across relationships? (250 to 500 words)

As a newly appointed Data Protection Officer of an IT company gearing up for DSCI’s privacy certification, you are trying to understand what data elements are involved in each of the business process, function and if these data elements can be classified as sensitive personal information. What is being accomplished with this effort?

A.

Organization to get “Visibility” over its exposure to sensitive personal information

B.

It is a part of the annual exercise per the organization’s privacy policy / processes

C.

Information security controls for confidential information being reviewed

D.

Gathering inputs to restructure privacy function

__________ calls for inclusion of data protection from the onset of the designing of systems.

A.

Agile Model

B.

Privacy by Design

C.

Logical Design

D.

Safeguarding Approach