QuestionQ308

Privacy Operational Lifecycle: Assess

Which maturity level should internal audit assign to Mesa’s privacy policies and procedures when using the Privacy Maturity Model (PMM)?

  • A Ad-hoc.
  • B Defined.
  • C Managed.
  • D Repeatable.
Explanation

Repeatable maturity applies when privacy procedures exist but are incomplete, insufficiently comprehensive, or not consistently implemented. Mesa has documented privacy roles and procedures, but they lack sound governance, complete organizational coverage, and appropriate implementation; they therefore do not meet the Defined or Managed levels.

Community Discussion

No comments yet. Be the first to start the discussion!