nerdexam
Isaca

CISA · Question #480

Which of the following is MOST important to determine when conducting an audit of an organization's data privacy practices?

The correct answer is C. Whether the systems inventory containing personal data is maintained. Maintaining a systems inventory of where personal data resides is the foundational element of any data privacy program. You cannot protect data you don't know about. Without a data inventory, controls like encryption (B and D) and disciplinary processes (A) cannot be applied effe

Submitted by rohit_dlh· Apr 18, 2026Information System Auditing Process

Question

Which of the following is MOST important to determine when conducting an audit of an organization's data privacy practices?

Options

  • AWhether a disciplinary process is established for data privacy violations
  • BWhether strong encryption algorithms are deployed for personal data protection
  • CWhether the systems inventory containing personal data is maintained
  • DWhether privacy technologies are implemented for personal data protection

How the community answered

(67 responses)
  • A
    15% (10)
  • B
    3% (2)
  • C
    72% (48)
  • D
    10% (7)

Explanation

Maintaining a systems inventory of where personal data resides is the foundational element of any data privacy program. You cannot protect data you don't know about. Without a data inventory, controls like encryption (B and D) and disciplinary processes (A) cannot be applied effectively or comprehensively. Data mapping and inventory are prerequisites for all other privacy controls and are required by major privacy regulations (e.g., GDPR Article 30). This makes it the most important thing to determine during a privacy audit.

Topics

#Data Privacy Audit#Data Inventory#Audit Planning#Personal Data Protection

Community Discussion

No community discussion yet for this question.

Full CISA Practice