CISSP · Question #619
An organization is considering outsourcing applications and data to a Cloud Service Provider (CSP). Which of the following is the MOST important concern regarding privacy?
The correct answer is D. The CSP may not be subject to the organization's country legation. Privacy is the right or ability of individuals or groups to control or limit the collection, use, disclosure, or retention of their personal or sensitive data by others. Privacy is an important concern for organizations that are considering outsourcing applications and data to…
Question
An organization is considering outsourcing applications and data to a Cloud Service Provider (CSP). Which of the following is the MOST important concern regarding privacy?
Options
- AThe CSP determines data criticality.
- BThe CSP provides end-to-end encryption services.
- CThe CSP's privacy policy may be developer by the organization.
- DThe CSP may not be subject to the organization's country legation.
How the community answered
(19 responses)- A16% (3)
- B21% (4)
- C5% (1)
- D58% (11)
Explanation
Privacy is the right or ability of individuals or groups to control or limit the collection, use, disclosure, or retention of their personal or sensitive data by others. Privacy is an important concern for organizations that are considering outsourcing applications and data to a Cloud Service Provider (CSP). The most important concern regarding privacy is that the CSP may not be subject to the organization's country legislation. The organization's country legislation may have specific laws, regulations, or standards that govern the privacy of data, such as the General Data Protection Regulation (GDPR) in the European Union, or the Health Insurance Portability and Accountability Act (HIPAA) in the United States. However, the CSP may operate in a different country or jurisdiction that has different or less stringent privacy laws, regulations, or standards. This may create a conflict or a gap between the organization's privacy obligations and the CSP's privacy practices, and expose the organization to legal, regulatory, or reputational risks. Therefore, the organization should carefully review the CSP's privacy policy and contract, and ensure that the CSP complies with the organization's country legislation and the organization's privacy requirements and expectations. The CSP determining data criticality, providing end-to- end encryption services, or allowing the organization to develop its privacy policy are not the most important concerns regarding privacy, as they are more related to data security, data protection, or data governance.
Topics
Community Discussion
No community discussion yet for this question.