ExamGecko
Question list
Search
Search

Related questions











Question 681 - CISA discussion

Report
Export

What should an IS auditor evaluate FIRST when reviewing an organization's response to new privacy legislation?

A.
Implementation plan for restricting the collection of personal information
Answers
A.
Implementation plan for restricting the collection of personal information
B.
Privacy legislation in other countries that may contain similar requirements
Answers
B.
Privacy legislation in other countries that may contain similar requirements
C.
Operational plan for achieving compliance with the legislation
Answers
C.
Operational plan for achieving compliance with the legislation
D.
Analysis of systems that contain privacy components
Answers
D.
Analysis of systems that contain privacy components
Suggested answer: D

Explanation:

The first thing that an IS auditor should evaluate when reviewing an organization's response to new privacy legislation is the analysis of systems that contain privacy components. Privacy components are elements of a system that collect, process, store, or transmit personal information that is subject to privacy legislation. An analysis of systems that contain privacy components should identify what types of personal information are involved, where they are located, how they are used, who has access to them, and what risks or threats they face. An analysis of systems that contain privacy components is essential for determining the scope and impact of the new privacy legislation on the organization's systems and processes.

The other options are not as important as option D. An implementation plan for restricting the collection of personal information is a possible action, but not the first thing to evaluate, when reviewing an organization's response to new privacy legislation. An implementation plan for restricting the collection of personal information is a document that outlines how an organization will comply with the principle of data minimization, which states that personal information should be collected only for specific and legitimate purposes and only to the extent necessary for those purposes. An implementation plan for restricting the collection of personal information should be based on an analysis of systems that contain privacy components. Privacy legislation in other countries that may contain similar requirements is a possible source of reference, but not the first thing to evaluate, when reviewing an organization's response to new privacy legislation. Privacy legislation in other countries that may contain similar requirements is a set of laws or regulations that governs the protection of personal information in other jurisdictions that may have comparable or compatible standards or expectations as the new privacy legislation. Privacy legislation in other countries that may contain similar requirements may provide guidance or best practices for complying with the new privacy legislation. However, privacy legislation in other countries that may contain similar requirements should not be used as a substitute for an analysis of systems that contain privacy components. An operational plan for achieving compliance with the legislation is a possible deliverable, but not the first thing to evaluate, when reviewing an organization's response to new privacy legislation. An operational plan for achieving compliance with the legislation is a document that describes how an organization will implement and maintain the necessary policies, procedures, controls, and measures to comply with the new privacy legislation. An operational plan for achieving compliance with the legislation should be derived from an analysis of systems that contain privacy components.Reference: Privacy law - Wikipedia,Data Protection and Privacy Legislation Worldwide | UNCTAD,Data minimization - Wikipedia

asked 18/09/2024
Arnaud DUTEL
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first