Identifying and Safeguarding
This flashcard set covers key concepts related to Privacy Impact Assessments (PIAs), Personally Identifiable Information (PII), federal guidance, and disclosure rules. It's designed to reinforce understanding of when PIAs are required, risks associated with PII, and what qualifies as protected information.
Which of the following must Privacy Impact Assessments (PIAs) do?
- Analyze how an organization handles information to ensure it satisfies requirements
-mitigate privacy risks
-determine the risks of collecting, using, maintaining, and disseminating PII on electronic information systems.
-all of the above
All of the Above
Key Terms
Which of the following must Privacy Impact Assessments (PIAs) do?
- Analyze how an organization handles information to ensure it satisfies requirements
-mitigate privacy risks
-determine the risks of collecting, using, maintaining, and disseminating PII on electronic information systems.
-all of the above
All of the Above
True or False? An Individual whose PII has been stolen is susceptible to identity theft, fraud, and other damage.
True
What / Which guidance identifies federal information security controls?
-The Freedom of Information Act (FOIA)
-The Privacy Act of 1974
-OMB Memorandum M-17-12: Preparing for and responding to a breach of PII
-DOD 5400.11-R: DOD Privacy Program
OMB Memorandum M-17-12
Which of the following is NOT an example of PII?
-Driver's License Number
-Pet's nickname
-Social Security Number
-Fingerprints
Pet's nickname
Which of the following is NOT a permitted disclosure of PII contained in a system of records?
-These are all permitted disclosures
-The record is disclosed for a new purpose that is not specified in the SORN
-The record is disclosed for routine use.
-The individual has requested that their record be disclosed.
The record is disclosed for a new purpose that is not specified in the SORN
PIA is required when organization collects PII from:
- Existing information systems and electronic collections for which no PIA was prev completed.
-New information systems or electronic collection...
Related Flashcard Decks
Study Tips
- Press F to enter focus mode for distraction-free studying
- Review cards regularly to improve retention
- Try to recall the answer before flipping the card
- Share this deck with friends to study together
| Term | Definition |
|---|---|
Which of the following must Privacy Impact Assessments (PIAs) do? | All of the Above |
True or False? An Individual whose PII has been stolen is susceptible to identity theft, fraud, and other damage. | True |
What / Which guidance identifies federal information security controls? | OMB Memorandum M-17-12 |
Which of the following is NOT an example of PII? | Pet's nickname |
Which of the following is NOT a permitted disclosure of PII contained in a system of records? | The record is disclosed for a new purpose that is not specified in the SORN |
PIA is required when organization collects PII from: | - Existing information systems and electronic collections for which no PIA was prev completed. |
PIA is not required when the information system or electronic collection: | - does not collect, maintain, or disseminate PII |
Within what timeframe must DOD organizations report PII breaches to the United States Computer Emergency Readiness Team (US-CERT) once discovered? | 1 hour for US-CERT |
Your organization has a new requirement for annual security training. To track training completion, they are using employee Social Security Numbers as record identification. Is this compliant with PII safeguarding procedures? | NO |
You are tasked with disposing of physical copies of last year's grant application forms. These documents contain PII so you use a cross-cut shredder to render them unrecognizable and beyond reconstruction. Is this compliant with PII safeguarding procedures? | YES |
Organizations that fail to maintain accurate, relevant, timely, and complete information may be subject to which of the following? | Civil Penalties |
True or False? Paper-based PP is involved in data breaches more often than electronic PP documentation? | False- Phishing is responsible for most of the recent PII Breaches |
Which regulation governs the DoD Privacy Program? | -DOD 5400.11-R: DOD Privacy Program |
Which of the following is NOT included in a breach notification? | A. Articles and other media reporting the breach. |
TRUE OR FALSE. A PIA is required if your system for storing PII is entirely on paper. | FALSE |
TRUE OR FALSE. Misuse of PII can result in legal liability of the individual | TRUE |
TRUE OR FALSE. Misuse of PII can result in legal liability of the organization. | TRUE |
Where is a System of Records Notice (SORN) filed? | Federal Register |
Organizations must report to Congress the status of their PII holdings every: | Year |
Jane Student is delivering a document that contains PII, but she cannot find the correct cover sheet. She should: | Mark the document CUI and wait to deliver it until she has the cover sheet |
The acronym PHI, in this context, refers to: | Protected Health Information |