CDPSE · Question #279
Which of the following should be the FIRST consideration prior to implementing an audit trail of access to personal data?
The correct answer is C. Cost-benefit analysis. Before implementing an audit trail-or any privacy control-an organization must first determine whether the investment is justified by the protection it provides. A cost-benefit analysis weighs the resources required (infrastructure, storage, personnel, maintenance) against the…
Question
Which of the following should be the FIRST consideration prior to implementing an audit trail of access to personal data?
Options
- AVulnerability and threat assessments
- BService level agreements (SLAs)
- CCost-benefit analysis
- DSensitivity and regulatory requirements
How the community answered
(63 responses)- A5% (3)
- B13% (8)
- C79% (50)
- D3% (2)
Explanation
Before implementing an audit trail-or any privacy control-an organization must first determine whether the investment is justified by the protection it provides. A cost-benefit analysis weighs the resources required (infrastructure, storage, personnel, maintenance) against the value gained (regulatory compliance, breach detection, accountability). Without this analysis, organizations risk over-engineering solutions or misallocating budgets. Sensitivity and regulatory requirements (D) and vulnerability assessments (A) feed into the cost-benefit analysis as inputs but do not replace it as the first consideration. SLAs (B) govern service delivery expectations and are a later operational concern.
Topics
Community Discussion
No community discussion yet for this question.