nerdexam
Isaca

CGEIT · Question #599

Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?

The correct answer is C. Consult the legal and compliance department. To ensure compliance and minimize mishandling of personal information under strict privacy regulations, it is best to consult the legal and compliance department for expert guidance.

Submitted by chiamaka_o· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?

Options

  • ARevise IT policies, standards, and procedures
  • BImplement a SIEM solution
  • CConsult the legal and compliance department
  • DEstablish new IT key risk indicators (KRIs)

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    4% (1)
  • C
    74% (20)
  • D
    7% (2)

Why each option

To ensure compliance and minimize mishandling of personal information under strict privacy regulations, it is best to consult the legal and compliance department for expert guidance.

ARevise IT policies, standards, and procedures

Revising IT policies is a subsequent action that should be informed by legal and compliance guidance, not the initial best way to understand and address legal requirements.

BImplement a SIEM solution

Implementing a SIEM solution is a technical control for monitoring security events, but it does not inherently prevent mishandling based on specific privacy regulations or ensure compliance with legal nuances.

CConsult the legal and compliance departmentCorrect

Consulting the legal and compliance department is the best first step because they possess specialized knowledge of the country's specific privacy regulations and can provide accurate, authoritative guidance on what constitutes mishandling and how to comply. This ensures that any subsequent actions are legally sound and effective.

DEstablish new IT key risk indicators (KRIs)

Establishing new KRIs is a measurement technique for risk, but it does not provide the initial expert guidance needed to understand and mitigate potential legal mishandling of data.

Concept tested: Data privacy compliance in regulated environments

Topics

#Privacy Regulations#Legal Compliance#Risk Management#IT Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice