CIPT Exam QuestionsBrowse all questions from this exam

CIPT Exam - Question 89


A company configures their information system to have the following capabilities:

✑ Allow for selective disclosure of attributes to certain parties, but not to others.

Permit the sharing of attribute references instead of attribute values - such as `I am over 21` instead of birthday date.

✑ Allow for information to be altered or deleted as needed.

These capabilities help to achieve which privacy engineering objective?

Show Answer
Correct Answer: B

The described capabilities align with the objective of Manageability in privacy engineering. Manageability involves the ability to administer personal information in a granular manner, including the modification, deletion, and controlled disclosure of attributes. It encompasses providing control over personal data, such as allowing selective sharing of attribute references instead of full attribute values, as well as the ability to alter or delete information as needed.

Discussion

5 comments
Sign in to comment
AhplOption: B
Mar 13, 2022

*it should be B - Manageability

837vq3Option: C
Oct 31, 2021

NIST’s Privacy Engineering Program has proposed three privacy engineering objectives: predictability, manageability and disassociability. Disassociability is the minimization of connections between data and individuals to the extent compatible with system operational requirements. This minimization can take many forms, from maximally disassociated data in the form of high-level aggregated data, to de-identified records pertaining to distinct individuals. Disassociability can also take the form of architectural data separation, in which identifiable personal information is kept segregated from, but still linkable to, transactional data

DoraaaaaaaaaOption: B
Jan 7, 2024

Manageability refers to the ability to granularly administer personal information, including modification, disclosure and deletion. Disassociability is the minimization of connections between data and individuals to the extent compatible with system operational requirements. .is minimization can take many forms, from maximally disassociated data in the form of high-level aggregated data, for example, to de-identified records pertaining to distinct individuals. Disassociability can also take the form of architectural data separation, in which identifiable.

z80rOption: C
Jan 22, 2023

C is correct

3444Option: C
Aug 23, 2023

C is correct