nerdexam
Isaca

CGEIT · Question #203

A health tech enterprise wants to ensure that its in-house developed mobile app for users complies with data privacy regulations. Which of the following should be identified FIRST when creating an…

The correct answer is C. Application and data owners. When creating an inventory of information systems and data for a mobile app to comply with data privacy regulations, the first step is to identify responsible parties.

Submitted by carlos_mx· Apr 18, 2026Governance of Enterprise IT

Question

A health tech enterprise wants to ensure that its in-house developed mobile app for users complies with data privacy regulations. Which of the following should be identified FIRST when creating an inventory of information systems and data related to the mobile app?

Options

  • AData maintained by vendors
  • BVendors and outsourced systems
  • CApplication and data owners
  • DInformation classification scheme

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    84% (31)
  • D
    5% (2)

Why each option

When creating an inventory of information systems and data for a mobile app to comply with data privacy regulations, the first step is to identify responsible parties.

AData maintained by vendors

Data maintained by vendors is a subset of the data that needs to be inventoried, but identifying the owners of all data provides the foundational accountability.

BVendors and outsourced systems

Identifying vendors and outsourced systems is important for a comprehensive inventory, but understanding internal data ownership precedes identifying external parties handling that data.

CApplication and data ownersCorrect

Identifying application and data owners is the crucial first step because these individuals or teams are ultimately accountable for the data and its compliance with regulations. They are responsible for defining data handling policies, understanding data sensitivity, and ensuring that privacy requirements are met throughout the data lifecycle, which is foundational for any compliance effort.

DInformation classification scheme

An information classification scheme defines data sensitivity, but it is typically developed or applied by the data owners, making owner identification a prerequisite for effective classification.

Concept tested: Data privacy compliance initial steps

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/control-data-security

Topics

#Data Governance#Information Inventory#Data Privacy Compliance#Accountability

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice