CISA · Question #586
Which of the following is an IS auditor's MOST important step in a privacy audit?
The correct answer is D. Analyze all stages of the personally identifiable information (PII) data life cycle to identify potential. The most important step in a privacy audit is to ensure that all risks associated with PII handling are identified. This requires analyzing the entire PII data life cycle--from collection, processing, storage, and transfer to retention and destruction. Option A: Reviewing data ma
Question
Which of the following is an IS auditor's MOST important step in a privacy audit?
Options
- AAssess the controls in place for data management.
- BDetermine whether privacy training is being conducted for employees.
- CReview third-party agreements for adequate personally identifiable information (PII) protection
- DAnalyze all stages of the personally identifiable information (PII) data life cycle to identify potential
How the community answered
(17 responses)- A18% (3)
- B6% (1)
- C6% (1)
- D71% (12)
Explanation
The most important step in a privacy audit is to ensure that all risks associated with PII handling are identified. This requires analyzing the entire PII data life cycle--from collection, processing, storage, and transfer to retention and destruction. Option A: Reviewing data management controls is part of the audit but is narrower than life cycle Option B: Privacy training is necessary, but training alone doesn't ensure compliance. Option C: Reviewing third-party agreements is important but only covers outsourced risks. Option D: Provides comprehensive coverage of privacy risks across all stages.
Topics
Community Discussion
No community discussion yet for this question.