nerdexam
Isaca

CISA · Question #627

An international organization collects customer data through internet-enabled fitness devices. Which of the following would be of GREATEST concern to an IS auditor reviewing the organization's…

The correct answer is C. The policy does not mention the jurisdiction under which the organization collects personal data. For an international organization collecting personal data, failing to identify the jurisdiction(s) under which data is collected is the most critical privacy policy gap. Jurisdiction determines which privacy laws apply (e.g., GDPR in the EU, PIPEDA in Canada, CCPA in…

Submitted by saadiq_pk· Apr 18, 2026Governance and Management of IT

Question

An international organization collects customer data through internet-enabled fitness devices. Which of the following would be of GREATEST concern to an IS auditor reviewing the organization’s privacy policy?

Options

  • AThe policy does not mention third-party audits performed for assurance purposes.
  • BThe policy does not include the technical details of security measures to protect customer data.
  • CThe policy does not mention the jurisdiction under which the organization collects personal data.
  • DThe policy does not offer clear mechanisms for users to opt out of data sharing.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    66% (21)
  • D
    22% (7)

Explanation

For an international organization collecting personal data, failing to identify the jurisdiction(s) under which data is collected is the most critical privacy policy gap. Jurisdiction determines which privacy laws apply (e.g., GDPR in the EU, PIPEDA in Canada, CCPA in California), what rights users have, how long data may be retained, and what breach notification obligations exist. Without this information, users cannot understand their legal protections or remedies. Not mentioning third-party audits (A) is not a standard policy requirement. Omitting technical security details (B) is actually appropriate-publishing technical controls can create security risks. Opt-out mechanisms (D) are important but may not apply universally depending on the legal basis for data collection.

Topics

#Privacy Policy#International Data Regulations#Jurisdiction#IS Audit Concerns

Community Discussion

No community discussion yet for this question.

Full CISA Practice