CRISC · Question #447
Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (PII)?
The correct answer is D. Local laws and regulations. When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations, due to the severe legal and financial repercussions of non-compliance.
Question
Which of the following should be the PRIMARY consideration when assessing the risk of using Internet of Things (loT) devices to collect and process personally identifiable information (PII)?
Options
- ABusiness strategies and needs
- BSecurity features and support
- CCosts and benefits
- DLocal laws and regulations
How the community answered
(32 responses)- A16% (5)
- B9% (3)
- C3% (1)
- D72% (23)
Why each option
When assessing the risk of IoT devices collecting PII, the primary consideration must be local laws and regulations, due to the severe legal and financial repercussions of non-compliance.
Business strategies and needs are important for determining if IoT is a good fit, but secondary to legal compliance when PII is involved.
Security features and support are critical for protecting PII, but their implementation is often guided by regulatory requirements, making regulations the overarching primary consideration.
Costs and benefits are financial considerations and, while important, do not outweigh the legal and ethical obligations associated with PII handling and regulatory compliance.
When dealing with Personally Identifiable Information (PII), especially through new technologies like IoT, compliance with local laws and regulations (such as GDPR, CCPA, HIPAA, etc.) is paramount. Failure to adhere to these data privacy laws can result in significant legal penalties, hefty fines, and severe reputational damage, making it the primary risk consideration.
Concept tested: Regulatory compliance for PII in IoT
Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr
Topics
Community Discussion
No community discussion yet for this question.