QuestionQ309

Privacy Operational Lifecycle: Assess

What was Liam’s key program-governance error before the audit kick-off meeting?

  • A He asked stakeholders to delete customer data out of the CRM tool.
  • B He met with stakeholders in marketing and E-commerce without the auditors.
  • C He did not obtain approval of the newly written policies from senior management.
  • D He did not properly escalate his concerns around the scope of the previous privacy review and develop a remediation plan with leadership support.
Explanation

Privacy risk management requires privacy-review scope gaps and residual risks to be escalated to organizational leadership so that risk treatment, resources, accountability, and any risk acceptance are formally determined. A remediation plan developed with leadership support was needed before implementing ad hoc changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!