nerdexam
Isaca

CISA · Question #538

During an audit of a project that involves a large number of records containing personal information, which of the following would BEST enable an IS auditor to analyze the associated privacy risks?

The correct answer is A. Data privacy impact assessment. A data privacy impact assessment (DPIA) systematically evaluates how personal information is collected, processed, stored, and protected within a project. It helps the IS auditor identify and analyze privacy risks, ensuring compliance with data protection regulations and minimizi

Submitted by ahmad_uae· Apr 18, 2026Protection of Information Assets

Question

During an audit of a project that involves a large number of records containing personal information, which of the following would BEST enable an IS auditor to analyze the associated privacy risks?

Options

  • AData privacy impact assessment
  • BPrivacy policy and standards
  • CInformation security risk register
  • DPrivacy contractual clauses

How the community answered

(42 responses)
  • A
    74% (31)
  • B
    7% (3)
  • C
    14% (6)
  • D
    5% (2)

Explanation

A data privacy impact assessment (DPIA) systematically evaluates how personal information is collected, processed, stored, and protected within a project. It helps the IS auditor identify and analyze privacy risks, ensuring compliance with data protection regulations and minimizing potential harm to individuals.

Topics

#Data Privacy Impact Assessment (DPIA)#Privacy Risk Analysis#IS Audit Techniques#Personal Information Protection

Community Discussion

No community discussion yet for this question.

Full CISA Practice