Podcast
Questions and Answers
Which action requires an organization to carry out a Privacy Impact Assessment?
Which action requires an organization to carry out a Privacy Impact Assessment?
Collecting PII to store in a new information system
Which of the following is an example of a physical safeguard that individuals can use to protect PII?
Which of the following is an example of a physical safeguard that individuals can use to protect PII?
- Locking office doors
- Shredding documents
- Using strong passwords
- All of the above (correct)
What is the purpose of a Privacy Impact Assessment (PIA)?
What is the purpose of a Privacy Impact Assessment (PIA)?
Determine whether the collection and maintenance of PII is worth the risk to individuals
Information that can be combined with other information to link solely to an individual is considered PII.
Information that can be combined with other information to link solely to an individual is considered PII.
What guidance identifies federal information security controls?
What guidance identifies federal information security controls?
An organization that fails to protect PII can face consequences including:
An organization that fails to protect PII can face consequences including:
If someone tampers with or steals an individual's PII, they could be exposed to which of the following?
If someone tampers with or steals an individual's PII, they could be exposed to which of the following?
Which of the following is NOT a permitted disclosure of PII contained in a system of records?
Which of the following is NOT a permitted disclosure of PII contained in a system of records?
Which of the following is not an example of PII?
Which of the following is not an example of PII?
Which of the following must privacy impact assessments (PIAs) do?
Which of the following must privacy impact assessments (PIAs) do?
What law establishes the federal government's legal responsibility for safeguarding PII?
What law establishes the federal government's legal responsibility for safeguarding PII?
Organizations that fail to maintain accurate, relevant, timely, and complete information may be subject to which of the following?
Organizations that fail to maintain accurate, relevant, timely, and complete information may be subject to which of the following?
What law establishes the public's right to access federal government information?
What law establishes the public's right to access federal government information?
An organization with existing system of records decides to start using PII for a new purpose outside the 'routine use' defined in the System of Records Notice (SORN). Is this a permitted use?
An organization with existing system of records decides to start using PII for a new purpose outside the 'routine use' defined in the System of Records Notice (SORN). Is this a permitted use?
A System of Records Notice (SORN) is not required if an organization determines that PII will be stored using a system of records.
A System of Records Notice (SORN) is not required if an organization determines that PII will be stored using a system of records.
Which of the following is responsible for the most recent PII data breaches?
Which of the following is responsible for the most recent PII data breaches?
Which of the following is not an example of an administrative safeguard that organizations use to protect PII?
Which of the following is not an example of an administrative safeguard that organizations use to protect PII?
Within what timeframe must DoD organizations report PII breaches to the United States Computer Emergency Readiness Team (US-CERT) once discovered?
Within what timeframe must DoD organizations report PII breaches to the United States Computer Emergency Readiness Team (US-CERT) once discovered?
Officials or employees who knowingly disclose PII to someone without a need-to-know may be subject to which of the following?
Officials or employees who knowingly disclose PII to someone without a need-to-know may be subject to which of the following?
Individuals who maintain a system of records without publishing the required public notice in the federal register may be subject to which of the following?
Individuals who maintain a system of records without publishing the required public notice in the federal register may be subject to which of the following?
Flashcards
PII
PII
Personally Identifiable Information; information that can be used to identify a specific individual.
PIA
PIA
Privacy Impact Assessment; evaluates risks and impacts of collecting and using PII.
Physical Safeguards
Physical Safeguards
Protections against loss or theft of PII in a physical environment.
OMB M-17-12
OMB M-17-12
Signup and view all the flashcards
System of Records Notice (SORN)
System of Records Notice (SORN)
Signup and view all the flashcards
Privacy Act of 1974
Privacy Act of 1974
Signup and view all the flashcards
FOIA
FOIA
Signup and view all the flashcards
Remediation Costs
Remediation Costs
Signup and view all the flashcards
Phishing
Phishing
Signup and view all the flashcards
Data Breaches
Data Breaches
Signup and view all the flashcards
Administrative Safeguards
Administrative Safeguards
Signup and view all the flashcards
Civil Penalties
Civil Penalties
Signup and view all the flashcards
Identity Theft
Identity Theft
Signup and view all the flashcards
US-CERT
US-CERT
Signup and view all the flashcards
Need-to-Know
Need-to-Know
Signup and view all the flashcards
Public Notices
Public Notices
Signup and view all the flashcards
Loss of Trust
Loss of Trust
Signup and view all the flashcards
Legal Liability
Legal Liability
Signup and view all the flashcards
Embaressment
Embaressment
Signup and view all the flashcards
Fraud
Fraud
Signup and view all the flashcards
Study Notes
Personally Identifiable Information (PII)
- Organizations must conduct a Privacy Impact Assessment (PIA) when collecting PII for a new information system.
- Physical safeguards to protect PII include various protective measures, with options for individuals to use all available methods.
- A PIA assesses the risks and impacts of collecting and maintaining PII in order to decide if the benefits outweigh the risks to individuals.
- PII in its broadest sense can be combined with other data to identify individuals, confirming that such information is classified as PII.
- The Office of Management and Budget (OMB) Memorandum M-17-12 outlines federal information security controls regarding PII breaches.
- Failing to protect PII can lead to remediation costs, loss of trust, legal liability, or all of the above.
- Individuals whose PII is stolen or tampered with may face embarrassment, fraud, or identity theft.
- Permitted disclosures of PII do not include records used for purposes not specified in the System of Records Notice (SORN).
- Examples of PII include fingerprints and Social Security numbers, while a pet's nickname does not qualify as PII.
- Privacy impact assessments must satisfy certain criteria to be considered valid and adequate.
- The Privacy Act of 1974 establishes the federal government’s responsibility to safeguard PII.
- Organizations that fail to maintain accurate and timely information may incur civil penalties.
- The Freedom of Information Act (FOIA) provides the public with the right to access federal government information.
- Using PII for purposes outside those defined in the SORN is not permitted.
- A System of Records Notice (SORN) is always required when PII is to be stored within a system of records.
- Phishing is the leading cause of recent PII data breaches, highlighting the need for effective cybersecurity measures.
- Administrative safeguards for PII do not include listing potential future uses of PII in a SORN.
- DoD organizations must report detected PII breaches to US-CERT within one hour.
- Disclosing PII without a need-to-know basis may lead to criminal penalties for officials or employees.
- Failure to publish required public notices for systems of records can result in both civil and criminal penalties.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Description
Test your knowledge on Personally Identifiable Information (PII) with these flashcards. Explore essential concepts like the Privacy Impact Assessment and various safeguards to protect PII. This quiz will help you understand critical aspects of PII compliance and security measures.