nerdexam
Isaca

CRISC · Question #447

Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (PII)?

The correct answer is D. Local laws and regulations. When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations, due to the severe legal and financial repercussions of non-compliance.

Submitted by parkjh· Apr 18, 2026IT Risk Assessment

Question

Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (PII)?

Options

  • ABusiness strategies and needs
  • BSecurity features and support
  • CCosts and benefits
  • DLocal laws and regulations

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    9% (3)
  • C
    3% (1)
  • D
    72% (23)

Why each option

When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations, due to the severe legal and financial repercussions of non-compliance.

ABusiness strategies and needs

Business strategies and needs are important for determining if IoT is a good fit, but secondary to legal compliance when PII is involved.

BSecurity features and support

Security features and support are critical for protecting PII, but their implementation is often guided by regulatory requirements, making regulations the overarching primary consideration.

CCosts and benefits

Costs and benefits are financial considerations and, while important, do not outweigh the legal and ethical obligations associated with PII handling and regulatory compliance.

DLocal laws and regulationsCorrect

When dealing with Personally Identifiable Information (PII), especially through new technologies like IoT, compliance with local laws and regulations (such as GDPR, CCPA, HIPAA, etc.) is paramount. Failure to adhere to these data privacy laws can result in significant legal penalties, hefty fines, and severe reputational damage, making it the primary risk consideration.

Concept tested: Regulatory compliance for PII in IoT

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr

Topics

#IoT Risk Management#PII Privacy#Regulatory Compliance#Risk Assessment Principles

Community Discussion

No community discussion yet for this question.

Full CRISC Practice