ExamGecko
Question list
Search
Search

Related questions

Question 282 - CISA discussion

Report
Export

Which of the following is the BEST source of information for an IS auditor to use as a baseline to assess the adequacy of an organization's privacy policy?

A.
Historical privacy breaches and related root causes
Answers
A.
Historical privacy breaches and related root causes
B.
Globally accepted privacy best practices
Answers
B.
Globally accepted privacy best practices
C.
Local privacy standards and regulations
Answers
C.
Local privacy standards and regulations
D.
Benchmark studies of similar organizations
Answers
D.
Benchmark studies of similar organizations
Suggested answer: C

Explanation:

The best source of information for an IS auditor to use as a baseline to assess the adequacy of an organization's privacy policy is the local privacy standards and regulations. Privacy standards and regulations are legal requirements that specify how personal data should be collected, processed, stored, shared, and disposed of by organizations. By using local privacy standards and regulations as a baseline, the IS auditor can ensure that the organization's privacy policy complies with the applicable laws and protects the rights and interests of data subjects. Historical privacy breaches and related root causes, globally accepted privacy best practices, and benchmark studies of similar organizations are useful sources of information for improving an organization's privacy policy, but they are not as authoritative and relevant as local privacy standards and regulations.Reference:CISA Review Manual (Digital Version): Chapter 2 - Governance and Management of Information Technology

asked 18/09/2024
Antonio Rodriguez
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first