Public assessment preview
AI, Data Protection, and Digital Security assignment brief.
This preview shows the practical shape of the certificate-track assessment without exposing the private answer key, scoring rubric, or certificate decision process.
Scenario
You support a small NGO team that uses shared drives, spreadsheets, survey tools, messaging apps, and AI-supported drafting. The team handles field notes, partner records, beneficiary feedback, staff documents, donor reports, and public communications.
Your task is to build and test a practical Digital Resilience Pack that helps this team protect people, maintain critical operations, make controlled tool decisions, and recover credibly when a safeguard fails.
Submit a nine-part Digital Resilience Pack
- One processing-activity and asset register covering at least four real types of organizational workflow.
- One classification and handling guide for public, internal, confidential, restricted, and high-consequence information.
- One documented decision on an AI, survey, storage, email, or collaboration tool, including evidence, unresolved gaps, restrictions, and an owner.
- One identity, access, sharing, device, and offboarding review for a defined team or project.
- One minimization and de-identification procedure, including a realistic contextual identification-risk check.
- One purpose-linked retention and deletion register with review dates, deletion evidence, and an exception route.
- One incident route covering detection, containment, evidence preservation, harm assessment, escalation, communication, and recovery.
- One tabletop exercise record that tests a plausible incident and records what failed, what worked, and what remained uncertain.
- One improvement plan with named owners, resources, deadlines, evidence tests, and retest dates.
Expected evidence
- Every component names a responsible owner and the decision it supports.
- Controls are proportionate to the people, information, operational dependency, and possible harm involved.
- Evidence distinguishes what was observed, what was assumed, what remains unresolved, and who accepted any residual risk.
- The tabletop record includes timestamps, handovers, communication decisions, restoration priorities, and follow-up actions.
- The final reflection identifies one practice to stop, one safeguard to introduce immediately, and one control that needs investment.
Boundary
Do not include real beneficiary names, survivor information, staff complaints, partner contracts, precise security locations, donor-confidential data, passwords, tokens, private links, or any other sensitive record in this assignment. Use fictional or redacted examples only.
This public brief does not issue a certificate and does not prove GDPR compliance or information-security certification. Any certificate decision requires verified enrollment, the required learning record, valid assessment evidence, administrative review, and a public verification record.