QuestionQ4

Privacy Operational Lifecycle: Assess

Regarding compliance with regulatory and legislative changes, which misconception does Anton have?

  • A The timeline for monitoring.
  • B The method of recordkeeping.
  • C The use of internal employees.
  • D The type of required qualifications.
Explanation

Privacy compliance requires ongoing monitoring and periodic reassessment because regulatory changes can require updates to policies and procedures. A one-time analysis cannot reliably establish compliance for the following five years. NIST’s privacy risk-management guidance describes continuous monitoring and updating to address changing requirements and risks.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!