nerdexam
(ISC)2

CISSP · Question #843

Which of the following controls is the FIRST step in protecting privacy in an information system?

The correct answer is B. Data Minimization. The first step in protecting privacy in an information system is data minimization. Data minimization is the principle and practice of collecting and processing only the minimum amount and type of data that is necessary and relevant for the intended purpose, and retaining the…

Submitted by dimitri_ru· Mar 5, 2026Security and Risk Management

Question

Which of the following controls is the FIRST step in protecting privacy in an information system?

Options

  • AData Redaction
  • BData Minimization
  • CData Encryption
  • DData Storage

How the community answered

(26 responses)
  • B
    88% (23)
  • C
    4% (1)
  • D
    8% (2)

Explanation

The first step in protecting privacy in an information system is data minimization. Data minimization is the principle and practice of collecting and processing only the minimum amount and type of data that is necessary and relevant for the intended purpose, and retaining the data only for the required duration. Data minimization reduces the risk and impact of data breaches, as well as the cost and complexity of data protection.

Topics

#data minimization#privacy principles#data protection#privacy controls

Community Discussion

No community discussion yet for this question.

Full CISSP Practice