What is a mission statement?
What is a vision statement?
How does a mission statement differ from a vision statement?
What factors influence the scope of a privacy program?
How can you identify data collected by the organization?
What are the 4 regulatory models?
How should organizations handle no or unknown legal requirements?
Apply the organization’s highest internal standards.
How is the United States regulatory model characterized?
Sector-specific and state-specific.
e.g., HIPAA, GLBA, CCPA
How is the EU, UK, and Canada regulatory model characterized?
Comprehensive; privacy is a fundamental right; enforced by official oversight agencies.
What is Australia’s approach to privacy regulation?
Co-regulatory; industry develops standards overseen by a privacy agency.
How is privacy regulation handled in countries like Japan and Singapore?
Self-regulatory; industry creates and enforces codes of practice.
e.g., TrustArc, WebTrust
What is a strategy?
A high-level plan outlining an organization’s data management and protection approach.
What is a privacy strategy?
A plan to communicate and support a privacy program’s mission and vision.
What are ISACA’s 5 components of a privacy strategy?
Why is privacy considered a team sport?
It requires buy-in from management, sales, and developers to shift organizational mindset.
What is the role of management in establishing a privacy strategy?
Provide funding for PETs, training, and awareness.
What is the developer’s role in a privacy strategy?
Implement Privacy by Design and Default in systems like websites and apps.
Which groups should be targeted to socialize a privacy strategy?
What is the purpose of conducting internal interviews?
Who is considered a ‘champion’ for the privacy program?
A program sponsor who advocates for resources and policies, respected, experienced.
e.g., CISO, CCO, GC
What are key components of relationship building in a privacy program?
Why are privacy workshops important?
What topics should be covered in a privacy workshop?
Why is it important to keep a record of ownership after workshops?
Supports: