CISM · Question #275
Which of the following is the BEST approach for addressing new regulatory requirements regarding personal data?
The correct answer is C. Treat compliance with the new regulations as any other risk. Treating new regulatory requirements as a risk (C) is correct because it applies the standard risk management lifecycle - identify, assess, prioritize, and respond - allowing the organization to evaluate compliance gaps, weigh the cost of non-compliance against remediation…
Question
Which of the following is the BEST approach for addressing new regulatory requirements regarding personal data?
Options
- ARecommend that management accept the risk of partial compliance.
- BMandate regulatory compliance throughout the organization.
- CTreat compliance with the new regulations as any other risk.
- DPurchase insurance to minimize noncompliance and reputational risk.
How the community answered
(60 responses)- A8% (5)
- B13% (8)
- C75% (45)
- D3% (2)
Explanation
Treating new regulatory requirements as a risk (C) is correct because it applies the standard risk management lifecycle - identify, assess, prioritize, and respond - allowing the organization to evaluate compliance gaps, weigh the cost of non-compliance against remediation costs, and allocate resources proportionally. This is the foundational approach endorsed by frameworks like COSO and ISO 31000.
Why the distractors fail:
- A is wrong because recommending risk acceptance for regulatory non-compliance is premature - you must first assess the full risk before accepting any portion of it, and regulators rarely accept partial compliance as a defense.
- B is wrong because mandating blanket compliance across the organization skips risk assessment; without prioritization, resources may be misallocated and the approach lacks the nuance to handle varying applicability across business units.
- D is wrong because insurance transfers only financial exposure - it does not address the underlying compliance obligation, reduce the likelihood of violations, or protect against reputational damage that insurance cannot fully cover.
Memory tip: Think "regulations are risks" - on ISACA/CISA exams, when regulators knock, the answer is almost never "ignore it" (A), "brute-force it" (B), or "pay someone else to care" (D); it's always "run the risk process."
Topics
Community Discussion
No community discussion yet for this question.