nerdexam
Isaca

CDPSE · Question #132

Which of the following should be done NEXT after a privacy risk has been accepted?

The correct answer is A. Monitor the risk landscape for material changes. Risk acceptance is not a permanent, set-and-forget decision. Once a risk is formally accepted, the organization must continuously monitor the risk landscape to detect material changes-such as new threat vectors, changes in applicable regulations, increased data volumes, or…

Privacy Governance

Question

Which of the following should be done NEXT after a privacy risk has been accepted?

Options

  • AMonitor the risk landscape for material changes.
  • BDetermine the risk appetite With management.
  • CAdjust the risk rating to help ensure it is remediated
  • DReconfirm the risk during the next reporting period

How the community answered

(22 responses)
  • A
    77% (17)
  • B
    5% (1)
  • C
    14% (3)
  • D
    5% (1)

Explanation

Risk acceptance is not a permanent, set-and-forget decision. Once a risk is formally accepted, the organization must continuously monitor the risk landscape to detect material changes-such as new threat vectors, changes in applicable regulations, increased data volumes, or evolving business processes-that could alter the original risk assessment. If conditions change significantly, the accepted risk may need to be re-evaluated or escalated. Determining risk appetite (B) and setting risk ratings (C) occur before the acceptance decision, not after. Reconfirming only during the next scheduled reporting period (D) is too passive and may miss time-sensitive changes.

Topics

#Privacy risk management#Risk acceptance#Risk monitoring#Continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice