ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 123 Topic 13 Discussion
CISSP Exam Topic 13 Question 123 Discussion:
Question #: 123
Topic #: 13
A security consultant has been asked to research an organization's legal obligations to protect privacy-related information. What kind of reading material is MOST relevant to this project?
A.
The organization's current security policies concerning privacy issues
B.
Privacy-related regulations enforced by governing bodies applicable to the organization
C.
Privacy best practices published by recognized security standards organizations
D.
Organizational procedures designed to protect privacy information
The most relevant reading material for researching an organization’s legal obligations to protect privacy-related information is the privacy-related regulations enforced by governing bodies applicable to the organization. These regulations define the legal requirements, standards, and penalties for collecting, processing, storing, and disclosing personal or sensitive information of individuals or entities. The organization must comply with these regulations to avoid legal liabilities, fines, or sanctions. The other options are not as relevant as privacy-related regulations, as they either do not reflect the legal obligations of the organization (A and C), or do not apply to all types of privacy-related information (D). References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 1, page 22; Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 1, page 31.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit