ExamGecko
Question list
Search
Search

Question 640 - CISM discussion

Report
Export

An international organization with remote branches is implementing a corporate security policy for managing personally identifiable information (PII). Which of the following should be the information security manager's MAIN concern?

A.
Local regulations
Answers
A.
Local regulations
B.
Data backup strategy
Answers
B.
Data backup strategy
C.
Consistency in awareness programs
Answers
C.
Consistency in awareness programs
D.
Organizational reporting structure
Answers
D.
Organizational reporting structure
Suggested answer: A

Explanation:

Local regulations are the main concern for the information security manager when implementing a corporate security policy for managing PII, as different countries or regions may have different legal, regulatory or contractual requirements for the protection, processing, storage and transfer of PII. The information security manager should ensure that the policy complies with the applicable local regulations and respects the rights and preferences of the data subjects. The policy should also address the risks and challenges of cross-border data transfers and the use of cloud services.

Reference= CISM Review Manual, 27th Edition, Chapter 4, Section 4.2.1, page 2191; CISM Online Review Course, Module 4, Lesson 2, Topic 12; Comparitech, PII Compliance: What is it and How to Implement it3

asked 01/10/2024
Ishan Patel
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first