CGEIT · Question #89
An enterprise plans to expand into new markets in countries lacking data privacy regulations, increasing risk exposure. Which of the following is the BEST course of action for the CIO?
The correct answer is A. Identify business risk appetite and tolerance levels.. When expanding into markets lacking data privacy regulations, the CIO's best initial course of action is to identify the enterprise's business risk appetite and tolerance levels. This foundational step will guide all subsequent risk management and strategic decisions regarding da
Question
An enterprise plans to expand into new markets in countries lacking data privacy regulations, increasing risk exposure. Which of the following is the BEST course of action for the CIO?
Options
- AIdentify business risk appetite and tolerance levels.
- BQuantify the risk impact and evaluate possible countermeasures.
- CLimit the personal data available to the high-risk countries.
- DMandate the strengthening of user access controls.
How the community answered
(44 responses)- A57% (25)
- B9% (4)
- C27% (12)
- D7% (3)
Why each option
When expanding into markets lacking data privacy regulations, the CIO's best initial course of action is to identify the enterprise's business risk appetite and tolerance levels. This foundational step will guide all subsequent risk management and strategic decisions regarding data handling in these new territories.
Before taking any specific mitigation steps, the CIO must first understand the enterprise's overall business risk appetite and tolerance levels. This strategic understanding defines how much risk the organization is willing to accept, which is crucial for guiding decisions on data handling, operational practices, and the allocation of resources for risk management in these new, unregulated markets.
Quantifying risk impact and evaluating countermeasures is an important step in risk management, but it should be informed by the business's pre-defined risk appetite and tolerance levels.
Limiting personal data is a potential countermeasure, but the decision to implement it should align with the established risk appetite; it's a solution, not the initial strategic assessment.
Mandating stronger user access controls is a specific technical control, which might be part of a solution, but it's premature before the overall risk appetite and strategic approach to data in these markets are defined.
Concept tested: Risk appetite and strategic decision-making
Source: https://www.isaca.org/resources/isaca-journal/issues/2019/volume-3/using-a-risk-appetite-statement-as-a-governance-tool
Topics
Community Discussion
No community discussion yet for this question.