nerdexam
Isaca

CISA · Question #586

Which of the following is an IS auditor's MOST important step in a privacy audit?

The correct answer is D. Analyze all stages of the personally identifiable information (PII) data life cycle to identify potential. The most important step in a privacy audit is to ensure that all risks associated with PII handling are identified. This requires analyzing the entire PII data life cycle--from collection, processing, storage, and transfer to retention and destruction. Option A: Reviewing data ma

Submitted by joshua94· Apr 18, 2026Information System Auditing Process

Question

Which of the following is an IS auditor's MOST important step in a privacy audit?

Options

  • AAssess the controls in place for data management.
  • BDetermine whether privacy training is being conducted for employees.
  • CReview third-party agreements for adequate personally identifiable information (PII) protection
  • DAnalyze all stages of the personally identifiable information (PII) data life cycle to identify potential

How the community answered

(17 responses)
  • A
    18% (3)
  • B
    6% (1)
  • C
    6% (1)
  • D
    71% (12)

Explanation

The most important step in a privacy audit is to ensure that all risks associated with PII handling are identified. This requires analyzing the entire PII data life cycle--from collection, processing, storage, and transfer to retention and destruction. Option A: Reviewing data management controls is part of the audit but is narrower than life cycle Option B: Privacy training is necessary, but training alone doesn't ensure compliance. Option C: Reviewing third-party agreements is important but only covers outsourced risks. Option D: Provides comprehensive coverage of privacy risks across all stages.

Topics

#Privacy audit#PII data life cycle#Audit methodology#Risk identification

Community Discussion

No community discussion yet for this question.

Full CISA Practice