CDPSE · Question #168
Which of the following is the BEST way to ensure an organization's enterprise risk management (ERM) framework can protect the organization from privacy harms?
The correct answer is D. Complete a privacy risk assessment. A privacy risk assessment systematically identifies, evaluates, and quantifies privacy-specific risks across the organization, producing outputs that can be directly fed into the ERM framework as actionable risk entries. This makes privacy risks visible, measurable, and…
Question
Which of the following is the BEST way to ensure an organization's enterprise risk management (ERM) framework can protect the organization from privacy harms?
Options
- AInclude privacy risks as a risk category.
- BEstablish a privacy incident response plan.
- CConduct an internal privacy audit.
- DComplete a privacy risk assessment.
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C5% (1)
- D81% (17)
Explanation
A privacy risk assessment systematically identifies, evaluates, and quantifies privacy-specific risks across the organization, producing outputs that can be directly fed into the ERM framework as actionable risk entries. This makes privacy risks visible, measurable, and manageable alongside other enterprise risks. Simply including privacy as a risk category (A) is too generic without the underlying assessment data to populate it. An incident response plan (B) is reactive and addresses privacy harms after they occur. An internal audit (C) evaluates existing controls but does not proactively identify and quantify risks in the way an assessment does.
Topics
Community Discussion
No community discussion yet for this question.