InterviewStack.io LogoInterviewStack.io
🛡️

Security Governance, Risk & Privacy Topics

Governance, compliance frameworks, regulatory requirements, compliance implementation, and compliance-driven risk management. Covers compliance frameworks (SOX, GDPR, HIPAA, FCPA, etc.), regulatory interpretation, compliance control design, audit and control effectiveness evaluation, and compliance process management. For operational security implementation and technical threat mitigation, see Security Engineering & Operations.

Audit Readiness, Evidence and Inspection Management

Preparing for internal and external audits and inspections, assembling the evidence auditors require, and managing the relationship with auditors, examiners, and regulators. Covers audit logging and evidence-collection strategy, sampling, maintaining continuous audit readiness and audit-trail integrity, coordinating fieldwork, responding to auditor requests, and handling adverse findings professionally. Both the make-it-demonstrable and the being-audited sides of assurance.

0 questions

Third-Party, Vendor and Supply Chain Risk

Assessing and governing the security and privacy risk introduced by vendors, processors, sub-processors, and the broader supply chain. Covers vendor risk assessment and due diligence, data processing agreements and contractual security and privacy requirements, ongoing third-party monitoring, procurement compliance, and fourth-party risk. The 'trust but verify your dependencies' discipline across both security and data-protection obligations.

0 questions

Health Data Privacy and HIPAA

Protecting health and medical data under HIPAA and equivalent sector rules: PHI, the Privacy and Security Rules, covered entities and business associates, and permitted uses and disclosures. Covers de-identification standards and safeguards specific to healthcare data. Includes how health-data constraints shape system and product design.

0 questions

Compliance Frameworks and Certification Standards

The major security compliance frameworks and how to achieve and maintain certification against them: SOC 2, ISO 27001, NIST CSF, NIST 800-53, CIS Controls, PCI DSS, and FedRAMP. Covers what each framework governs, how control families map to organizational practices, and how to scope, prepare for, and pass a certification assessment. Emphasizes framework selection and reconciling overlapping control requirements across standards.

0 questions

Privacy-Preserving Analytics and Experimentation

Doing measurement and data science without over-collecting or exposing individuals: privacy-preserving experiment design, aggregate and on-device measurement, and privacy-respecting attribution. Covers techniques for analytics and A/B testing that limit personal-data use and honor consent. Includes reconciling measurement quality with privacy constraints.

0 questions

Security and Privacy Culture, Training and Awareness

Building organization-wide security and privacy awareness and a culture where protective behavior is the norm. Covers awareness and role-based training programs, phishing simulations, embedding security and privacy ownership into engineering, product, and support teams, and measuring and improving culture. Focuses on the human layer of the program rather than technical controls.

0 questions

Data Breach and Privacy Incident Response

Responding to privacy incidents and breaches: detection, containment, investigation, severity and breach classification, and regulator and individual notification within statutory deadlines. Covers complaint intake and resolution, escalation, and balancing transparency against risk during an incident. Includes coordinating the cross-functional response and post-incident remediation.

0 questions

Data Subject Rights and Request Handling

Operationalizing individual rights: access, rectification, erasure, portability, restriction, and objection requests. Covers identity verification, response timelines, locating data across systems to fulfill a request, and handling edge cases and exemptions. Includes designing systems that can execute deletion and export reliably at scale.

0 questions

Compliance Investigation and Legal Collaboration

Investigating suspected compliance violations and coordinating with legal, security, and law enforcement. Covers compliance investigation methodology, evidence handling and chain of custody for compliance matters, escalation and disciplinary decision making, and working with legal counsel and external authorities. The investigate-and-enforce side of a compliance function.

0 questions
Page 1/5