Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

DCPLA DSCI Certified Privacy Lead Assessor Questions and Answers

Questions 4

Which of the following does the ‘Privacy Strategy & Processes’ layer in the DPF help accomplish? (Choose all that apply.)

Options:

A.

Visibility over Personal Information

B.

Privacy Policy and Processes

C.

Regulatory Compliance Intelligence

D.

Information Usage and Access

E.

Personal Information Security

Buy Now
Questions 5

The method of personal data usage in which the users must explicitly decide not to participate.

Options:

A.

Opt-In

B.

Opt-out

C.

Data mining

D.

Data matching

Buy Now
Questions 6

Which of the following measures can an organization implement to establish regulatory compliance intelligence? (Choose all that apply.)

Options:

A.

Establish a process that keeps a track of applicable legal and regulatory changes

B.

Identify the liabilities imposed by the regulations with respect to specific data elements

C.

Ensure that a mechanism exists for quick and effective provisioning, de-provisioning and authorization of access to information or systems which are exposed to data

D.

Ensure that knowledge with respect to legal and regulatory compliances is managed effectively

Buy Now
Questions 7

Which of the following activities form part of an organization’s Visibility over Personal Information (VPI) initiative, according to DSCI Privacy Framework (DPF®)?

Options:

A.

‘Data processing environment’ analysis of industry peers

B.

‘Data processing environment’ analysis of the country

C.

‘Data processing environment’ analysis of the organization and associated third parties

D.

‘Data processing environment' analysis of the organization only

Buy Now
Questions 8

Which of the following are key contributors that would enhance the complexity in implementing security measures for protection of personal information? (Choose all that apply.)

Options:

A.

Data collection through multiple modes and channels

B.

Evolution of nimble and flexible business processes affecting access management

C.

Regulatory requirements to issue privacy notice and data breach notification in specified format

D.

None of the above

Buy Now
Questions 9

Which of the following mechanisms can be used to transfer personal data outside of a country?

Options:

A.

Binding corporate rules

B.

Adequacy decision

C.

Standard contractual clauses

D.

All of the above

Buy Now
Questions 10

FILL BLANK

PIS

The company has a well-defined and effectively implemented security policy. As in case of access control, the security controls vary in different client relationships based on the client requirements but certain basic or hygiene security practices / controls are implemented organization wide. The consultants have advised the information security function to realign the company’s security policy, risk assessment, data classification, etc to include privacy aspects. But the consultants are struggling to make information security function understand what exact changes need to be made and the security function itself is unable to figure it out.

(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a definitive conclusion)

Introduction and Background

XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom among others in Americas, Europe, Asia-Pacific, Middle East and Africa. The company provides IT services including application development and maintenance, IT Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI customers.

The company is witnessing phenomenal growth in the BPM services over last few years including Finance & Accounting including credit card processing, Payroll processing, Customer support, Legal Process Outsourcing, among others and has rolled out platform based services. Most of the company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the company is looking to expand its operations in Europe. India, too has attracted company’s attention given the phenomenal increase in domestic IT spend esp. by the government through various large scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong focus on delivery of cloud services. When it comes to expanding operations in Europe, company is facing difficulties in realizing the full potential of the market because of privacy related concerns of the clients arising from the stringent regulatory requirements based on EU General Data Protection Regulation (EU GDPR).

To get better access to this market, the company decided to invest in privacy, so that it is able to provide increased assurance to potential clients in the EU and this will also benefit its US operations because privacy concerns are also on rise in the US. It will also help company leverage outsourcing opportunities in the Healthcare sector in the US which would involve protection of sensitive medical records of the US citizens. The company believes that privacy will also be a key differentiator in the cloud business going forward. In short, privacy was taken up as a strategic initiative in the company in early 2011.

Since XYZ had an internal consulting arm, it assigned the responsibility of designing and implementing an enterprise wide privacy program to the consulting arm. The consulting arm had very good expertise in information security consulting but had limited expertise in the privacy domain. The project was to be driven by CIO's office, in close consultation with the Corporate Information Security and Legal functions.

Can you please guide the information security function to realign company’s security initiatives to include privacy protection, keeping in mind that the client security requirements would vary across relationships? (250 to 500 words)

Options:

Buy Now
Exam Code: DCPLA
Exam Name: DSCI Certified Privacy Lead Assessor
Last Update: Apr 16, 2024
Questions: 70

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now DCPLA testing engine

PDF (Q&A)

$35  $99.99
buy now DCPLA pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 23 Apr 2024