The correct answer is C. Percentage of privacy impact assessments (PIAs) completed.
A privacy impact assessment is a proactive privacy risk-management activity. ISACA defines a PIA as the overall process of identifying, analyzing, evaluating, consulting, communicating, and planning the treatment of potential privacy impacts related to processing personally identifiable information within the broader enterprise risk management framework. Therefore, the percentage of required PIAs completed is a strong indicator that the privacy program is being applied to systems, processes, and data-processing activities.
Option A is not the best answer because training completion measures participation or awareness, not whether privacy risks are being assessed and treated. Option B is not the best answer because attempted privacy breaches may reflect the threat environment rather than the effectiveness of the privacy program. Option D is not the best answer because deletion requests are data subject activity; they do not directly demonstrate whether the privacy program is effective.
This question maps mainly to Protection of Information Assets, because ISACA’s CISA Exam Content Outline includes information asset security, privacy principles, data protection, and security monitoring under Domain 5.
[References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, “Privacy impact assessment.”, ===================, ]
Submit