CDPSE · Question #430
Which of the following BEST enables an organization to establish a comprehensive privacy risk management framework?
The correct answer is C. Leveraging industry standards and best practices. Industry standards and best practices - such as the NIST Privacy Framework, ISO 27701, or OECD Privacy Guidelines - provide structured, comprehensive, and proven methodologies for building a privacy risk management program. They incorporate regulatory requirements, risk…
Question
Which of the following BEST enables an organization to establish a comprehensive privacy risk management framework?
Options
- ALeveraging existing privacy policies as a foundation
- BEnsuring appropriate metrics are established and monitored
- CLeveraging industry standards and best practices
- DProviding adequate notice of privacy breaches to stakeholders
How the community answered
(20 responses)- A10% (2)
- B5% (1)
- C85% (17)
Explanation
Industry standards and best practices - such as the NIST Privacy Framework, ISO 27701, or OECD Privacy Guidelines - provide structured, comprehensive, and proven methodologies for building a privacy risk management program. They incorporate regulatory requirements, risk assessment approaches, and controls in a holistic way. Existing policies (A) may be incomplete or outdated. Metrics (B) are a monitoring tool within a framework, not the foundation of one. Breach notification (D) is a reactive, specific obligation, not a framework-building activity.
Topics
Community Discussion
No community discussion yet for this question.