nerdexam
Isaca

CGEIT · Question #356

A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following shoul

The correct answer is D. Mandate the creation of a data privacy policy.. After defining a data governance strategy with privacy objectives, the next step for the committee is to mandate the creation of a detailed data privacy policy.

Submitted by noor.lb· Apr 18, 2026Governance of Enterprise IT

Question

A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?

Options

  • AMandate data privacy training for employees.
  • BEstablish a data privacy budget
  • CPerform a data privacy impact assessment.
  • DMandate the creation of a data privacy policy.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    7% (3)
  • C
    17% (7)
  • D
    71% (30)

Why each option

After defining a data governance strategy with privacy objectives, the next step for the committee is to mandate the creation of a detailed data privacy policy.

AMandate data privacy training for employees.

Mandating training is an implementation step that follows the creation of a policy, as training content would be based on the established policy.

BEstablish a data privacy budget

Establishing a budget is a supporting activity for implementation, but the policy itself defines what needs to be budgeted for.

CPerform a data privacy impact assessment.

Performing a data privacy impact assessment (DPIA) is a process used for specific projects or systems to evaluate privacy risks, and it would be guided by an overarching data privacy policy.

DMandate the creation of a data privacy policy.Correct

A data privacy policy translates the high-level strategy and objectives into specific rules and guidelines for how the organization handles personal data, providing a framework for operationalizing privacy controls. This policy outlines responsibilities, procedures, and standards for access, use, and collection, ensuring consistent application across the enterprise.

Concept tested: Data governance implementation steps

Source: https://learn.microsoft.com/en-us/industry/financial/digital-governance-strategy-for-financial-services-architecture-guide#policy-development-and-enforcement

Topics

#Data Governance#Privacy Strategy#Policy Development#IT Governance Process

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice