nerdexam
Isaca

CDPSE · Question #279

Which of the following should be the FIRST consideration prior to implementing an audit trail of access to personal data?

The correct answer is C. Cost-benefit analysis. Before implementing an audit trail-or any privacy control-an organization must first determine whether the investment is justified by the protection it provides. A cost-benefit analysis weighs the resources required (infrastructure, storage, personnel, maintenance) against the…

Privacy Governance

Question

Which of the following should be the FIRST consideration prior to implementing an audit trail of access to personal data?

Options

  • AVulnerability and threat assessments
  • BService level agreements (SLAs)
  • CCost-benefit analysis
  • DSensitivity and regulatory requirements

How the community answered

(63 responses)
  • A
    5% (3)
  • B
    13% (8)
  • C
    79% (50)
  • D
    3% (2)

Explanation

Before implementing an audit trail-or any privacy control-an organization must first determine whether the investment is justified by the protection it provides. A cost-benefit analysis weighs the resources required (infrastructure, storage, personnel, maintenance) against the value gained (regulatory compliance, breach detection, accountability). Without this analysis, organizations risk over-engineering solutions or misallocating budgets. Sensitivity and regulatory requirements (D) and vulnerability assessments (A) feed into the cost-benefit analysis as inputs but do not replace it as the first consideration. SLAs (B) govern service delivery expectations and are a later operational concern.

Topics

#Cost-benefit analysis#Privacy control implementation#Audit trails#Privacy program management

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice