nerdexam
Isaca

CDPSE · Question #386

Which of the following is the FIRST step to protect data subject privacy when planning the deployment of a public monitoring system?

The correct answer is C. Conduct a privacy impact assessment (PIA). Conducting a Privacy Impact Assessment is the mandatory first step before deploying any public monitoring system, as it identifies privacy risks before design and deployment decisions are finalized.

Data Life Cycle

Question

Which of the following is the FIRST step to protect data subject privacy when planning the deployment of a public monitoring system?

Options

  • AInform the public of the project.
  • BDraft a privacy breach response plan.
  • CConduct a privacy impact assessment (PIA).
  • DInform data protection authorities.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    93% (41)

Why each option

Conducting a Privacy Impact Assessment is the mandatory first step before deploying any public monitoring system, as it identifies privacy risks before design and deployment decisions are finalized.

AInform the public of the project.

Informing the public is an important step but occurs after the PIA has determined what data is collected, what risks exist, and how the public should be notified.

BDraft a privacy breach response plan.

Drafting a breach response plan is a later risk management activity that depends on the risk findings from the PIA being completed first.

CConduct a privacy impact assessment (PIA).Correct

A PIA systematically identifies, evaluates, and addresses privacy risks introduced by a new system before it is built or deployed, ensuring privacy is embedded by design. For a public monitoring system, a PIA determines what data is collected, from whom, for what purpose, and what risks exist - informing all subsequent decisions. Completing the PIA first ensures that notifications to the public, authorities, and breach plans are grounded in an accurate understanding of the system's privacy implications.

DInform data protection authorities.

Notifying data protection authorities may be required as a result of PIA findings but cannot be done accurately before the PIA establishes what the system does and what risks it poses.

Concept tested: Privacy Impact Assessment as first step in system deployment

Source: https://www.nist.gov/privacy-framework

Topics

#Privacy Impact Assessment#Privacy by Design#Privacy Risk Management#Data Protection Planning

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice