QuestionQ1261

Risk Response and Reporting

A highly regulated organization has acquired a medical technology startup that processes sensitive personal information using weak data-protection controls.

Which of the following is the BEST way for the acquiring company to reduce its risk while still providing the flexibility required by the startup company?

  • A Implement a firewall and isolate the environment from the parent company's network.
  • B Classify and protect the data according to the parent company's internal standards.
  • C Have the data privacy officer review the startup company's data protection policies.
  • D Identify previous data breaches using the startup company's audit reports.
Explanation

Classifying the sensitive personal information and protecting it under the acquiring organization’s internal standards establishes consistent, risk-based requirements for data handling, access, and safeguards. This reduces exposure while allowing the startup to operate within an appropriate governance framework.

Community Discussion

No comments yet. Be the first to start the discussion!