Isaca Certified in Risk and Information Systems Control CRISC Question # 372 Topic 38 Discussion
CRISC Exam Topic 38 Question 372 Discussion:
Question #: 372
Topic #: 38
What should be the PRIMARY consideration related to data privacy protection when there are plans for a business initiative to make use of personal information?
A.
Do not collect or retain data that is not needed.
B.
Redact data where possible.
C.
Limit access to the personal data.
D.
Ensure all data is encrypted at rest and during transit.
Data privacy protection is the process of safeguarding the personal information of individuals from unauthorized access, use, disclosure, modification, or destruction. Personal information is any information that can be used to identify, locate, or contact an individual, such as name, address, phone number, email, social security number, etc. When there are plans for a business initiative to make use of personal information, the primary consideration related to data privacyprotection is to do not collect or retain data that is not needed. This means that the organization should only collect the minimum amount of personal information that is necessary for the purpose of the business initiative, and should only retain the data for as long as it is required by law or business needs. By doing so, the organization can reduce the risk of data breaches,comply with the data protection regulations, respect the data subjects’ rights, and enhance the trust and reputation of the organization. References = CRISC Review Manual, 7th Edition, page 159.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit