Isaca Certified in Risk and Information Systems Control CRISC Question # 362 Topic 37 Discussion
CRISC Exam Topic 37 Question 362 Discussion:
Question #: 362
Topic #: 37
A data privacy regulation has been revised to incorporate more stringent requirements for personal data protection. Which of the following provides the MOST important input to help ensure compliance with the revised regulation?
Gap analysisidentifies differences between existing controls and the new regulatory requirements.
CRISC guidance explains:
“When a regulatory or compliance requirement changes, the first step is to conduct a gap analysis comparing current controls to the new requirements.”
This allows the practitioner to identify areas requiring remediation or policy enhancement.
Hence,A. Gap analysisis correct.
CRISC Reference:Domain 3 – Risk Response and Mitigation, Topic: Compliance and Regulatory Alignment.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit