QuestionQ118

Privacy Operational Lifecycle: Assess

What is the most likely reason the Chief Information Officer (CIO) believes that creating a list of required IT equipment is not sufficient?

  • A The company needs to have policies and procedures in place to guide the purchasing decisions.
  • B The privacy notice for customers and the Business Continuity Plan (BCP) still need to be reviewed.
  • C Staff members across departments need time to review technical information concerning any new databases.
  • D Senior staff members need to first commit to adopting a minimum number of Privacy Enhancing Technologies (PETs).
Explanation

Privacy compliance requires policies and procedures that define data-handling requirements, responsibilities, safeguards, and procurement criteria. Those controls guide which IT equipment is appropriate; equipment by itself cannot create an effective privacy program.

Community Discussion

No comments yet. Be the first to start the discussion!