Podcast
Questions and Answers
Which action requires an organization to carry out a Privacy Impact Assessment?
Which action requires an organization to carry out a Privacy Impact Assessment?
Collecting PII to store in a new information system
Which of the following is an example of a physical safeguard that individuals can use to protect PII?
Which of the following is an example of a physical safeguard that individuals can use to protect PII?
What is the purpose of a Privacy Impact Assessment (PIA)?
What is the purpose of a Privacy Impact Assessment (PIA)?
Determine whether the collection and maintenance of PII is worth the risk to individuals
Information that can be combined with other information to link solely to an individual is considered PII.
Information that can be combined with other information to link solely to an individual is considered PII.
Signup and view all the answers
What guidance identifies federal information security controls?
What guidance identifies federal information security controls?
Signup and view all the answers
An organization that fails to protect PII can face consequences including:
An organization that fails to protect PII can face consequences including:
Signup and view all the answers
If someone tampers with or steals an individual's PII, they could be exposed to which of the following?
If someone tampers with or steals an individual's PII, they could be exposed to which of the following?
Signup and view all the answers
Which of the following is NOT a permitted disclosure of PII contained in a system of records?
Which of the following is NOT a permitted disclosure of PII contained in a system of records?
Signup and view all the answers
Which of the following is not an example of PII?
Which of the following is not an example of PII?
Signup and view all the answers
Which of the following must privacy impact assessments (PIAs) do?
Which of the following must privacy impact assessments (PIAs) do?
Signup and view all the answers
What law establishes the federal government's legal responsibility for safeguarding PII?
What law establishes the federal government's legal responsibility for safeguarding PII?
Signup and view all the answers
Organizations that fail to maintain accurate, relevant, timely, and complete information may be subject to which of the following?
Organizations that fail to maintain accurate, relevant, timely, and complete information may be subject to which of the following?
Signup and view all the answers
What law establishes the public's right to access federal government information?
What law establishes the public's right to access federal government information?
Signup and view all the answers
An organization with existing system of records decides to start using PII for a new purpose outside the 'routine use' defined in the System of Records Notice (SORN). Is this a permitted use?
An organization with existing system of records decides to start using PII for a new purpose outside the 'routine use' defined in the System of Records Notice (SORN). Is this a permitted use?
Signup and view all the answers
A System of Records Notice (SORN) is not required if an organization determines that PII will be stored using a system of records.
A System of Records Notice (SORN) is not required if an organization determines that PII will be stored using a system of records.
Signup and view all the answers
Which of the following is responsible for the most recent PII data breaches?
Which of the following is responsible for the most recent PII data breaches?
Signup and view all the answers
Which of the following is not an example of an administrative safeguard that organizations use to protect PII?
Which of the following is not an example of an administrative safeguard that organizations use to protect PII?
Signup and view all the answers
Within what timeframe must DoD organizations report PII breaches to the United States Computer Emergency Readiness Team (US-CERT) once discovered?
Within what timeframe must DoD organizations report PII breaches to the United States Computer Emergency Readiness Team (US-CERT) once discovered?
Signup and view all the answers
Officials or employees who knowingly disclose PII to someone without a need-to-know may be subject to which of the following?
Officials or employees who knowingly disclose PII to someone without a need-to-know may be subject to which of the following?
Signup and view all the answers
Individuals who maintain a system of records without publishing the required public notice in the federal register may be subject to which of the following?
Individuals who maintain a system of records without publishing the required public notice in the federal register may be subject to which of the following?
Signup and view all the answers
Study Notes
Personally Identifiable Information (PII)
- Organizations must conduct a Privacy Impact Assessment (PIA) when collecting PII for a new information system.
- Physical safeguards to protect PII include various protective measures, with options for individuals to use all available methods.
- A PIA assesses the risks and impacts of collecting and maintaining PII in order to decide if the benefits outweigh the risks to individuals.
- PII in its broadest sense can be combined with other data to identify individuals, confirming that such information is classified as PII.
- The Office of Management and Budget (OMB) Memorandum M-17-12 outlines federal information security controls regarding PII breaches.
- Failing to protect PII can lead to remediation costs, loss of trust, legal liability, or all of the above.
- Individuals whose PII is stolen or tampered with may face embarrassment, fraud, or identity theft.
- Permitted disclosures of PII do not include records used for purposes not specified in the System of Records Notice (SORN).
- Examples of PII include fingerprints and Social Security numbers, while a pet's nickname does not qualify as PII.
- Privacy impact assessments must satisfy certain criteria to be considered valid and adequate.
- The Privacy Act of 1974 establishes the federal government’s responsibility to safeguard PII.
- Organizations that fail to maintain accurate and timely information may incur civil penalties.
- The Freedom of Information Act (FOIA) provides the public with the right to access federal government information.
- Using PII for purposes outside those defined in the SORN is not permitted.
- A System of Records Notice (SORN) is always required when PII is to be stored within a system of records.
- Phishing is the leading cause of recent PII data breaches, highlighting the need for effective cybersecurity measures.
- Administrative safeguards for PII do not include listing potential future uses of PII in a SORN.
- DoD organizations must report detected PII breaches to US-CERT within one hour.
- Disclosing PII without a need-to-know basis may lead to criminal penalties for officials or employees.
- Failure to publish required public notices for systems of records can result in both civil and criminal penalties.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Description
Test your knowledge on Personally Identifiable Information (PII) with these flashcards. Explore essential concepts like the Privacy Impact Assessment and various safeguards to protect PII. This quiz will help you understand critical aspects of PII compliance and security measures.