nerdexam
Isaca

CISA · Question #31

Which of the following is MOST important to consider when assessing the scope of privacy concerns for an IT project?

The correct answer is B. Applicable laws and regulations. When assessing privacy concerns for an IT project, the most critical consideration is the set of applicable laws and regulations that dictate how personal data must be handled. These legal frameworks define the baseline for privacy obligations and compliance.

Submitted by ricky.ec· Apr 18, 2026Governance and Management of IT

Question

Which of the following is MOST important to consider when assessing the scope of privacy concerns for an IT project?

Options

  • ABusiness requirements and data flows
  • BApplicable laws and regulations
  • CData ownership
  • DEnd user access rights

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    78% (36)
  • C
    2% (1)
  • D
    13% (6)

Why each option

When assessing privacy concerns for an IT project, the most critical consideration is the set of applicable laws and regulations that dictate how personal data must be handled. These legal frameworks define the baseline for privacy obligations and compliance.

ABusiness requirements and data flows

Business requirements and data flows define how data is processed, but do not establish the legal privacy boundaries themselves.

BApplicable laws and regulationsCorrect

Applicable laws and regulations are paramount because they establish the mandatory legal framework and minimum requirements for data protection and privacy (e.g., GDPR, CCPA) that any IT project handling personal data must adhere to. Non-compliance can lead to severe penalties and reputational damage, making them the foundational element for scope assessment.

CData ownership

Data ownership is important for accountability but does not unilaterally define the scope of privacy concerns in a legal or regulatory sense.

DEnd user access rights

End user access rights are a control mechanism for data access, which is a component of privacy but not the primary driver for defining its overall scope.

Concept tested: Privacy regulations compliance scope

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr

Topics

#Privacy#Legal and Regulatory Compliance#IT Project Assessment#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice