QuestionQ217

Privacy Operational Lifecycle: Assess

Which type of audit would be most appropriate to recommend for Gadgo?

  • A A supplier audit.
  • B An internal audit.
  • C A third-party audit.
  • D A self-certification.
Explanation

A third-party audit provides an independent, impartial evaluation of privacy and data-protection practices. It is appropriate where weak, inconsistent controls and leadership resistance create a need for credible external assurance rather than a self-assessment or an audit focused on suppliers. NIST describes third-party assessments as being performed by independent entities and as appropriate when higher assurance is needed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!