nerdexam
Isaca

CRISC · Question #342

Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (Pll)?

The correct answer is B. Local laws and regulations. When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations due to the legal and compliance implications of handling sensitive personal data.

Submitted by devops_kid· Apr 18, 2026IT Risk Assessment

Question

Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (Pll)?

Options

  • ACosts and benefits
  • BLocal laws and regulations
  • CSecurity features and support
  • DBusiness strategies and needs

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    92% (47)
  • C
    2% (1)
  • D
    2% (1)

Why each option

When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations due to the legal and compliance implications of handling sensitive personal data.

ACosts and benefits

Costs and benefits are business considerations but secondary to legal compliance when PII is involved.

BLocal laws and regulationsCorrect

Handling Personally Identifiable Information (PII) is subject to strict legal and regulatory frameworks globally (e.g., GDPR, CCPA). Non-compliance can lead to severe penalties, legal liabilities, and reputational damage, making local laws and regulations the paramount consideration when assessing risk.

CSecurity features and support

Security features are crucial for protecting PII but are often dictated by or evaluated against legal and regulatory requirements.

DBusiness strategies and needs

Business strategies and needs drive the use of IoT but must operate within the bounds of legal and regulatory compliance concerning PII.

Concept tested: PII regulatory compliance in IoT

Topics

#IoT Risk#PII Protection#Regulatory Compliance#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CRISC Practice