CRISC · Question #554
An organization needs to send files to a business partner to perform a quality control audit on the organization's record-keeping processes. The files include personal information on…
The correct answer is A. Obfuscate the customers' personal information. Obfuscating personal information is the best recommendation to mitigate privacy risk when sharing data with a third party, as it reduces the identifiability of the data while potentially retaining its utility for the task.
Question
An organization needs to send files to a business partner to perform a quality control audit on the organization's record-keeping processes. The files include personal information on theorganization's customers. Which of the following is the BEST recommendation to mitigate privacy risk?
Options
- AObfuscate the customers' personal information.
- BRequire the business partner to delete personal information following the audit.
- CUse a secure channel to transmit the files.
- DEnsure the contract includes provisions for sharing personal information.
How the community answered
(41 responses)- A56% (23)
- B27% (11)
- C12% (5)
- D5% (2)
Why each option
Obfuscating personal information is the best recommendation to mitigate privacy risk when sharing data with a third party, as it reduces the identifiability of the data while potentially retaining its utility for the task.
Obfuscating or anonymizing personal information directly mitigates privacy risk by making the data less identifiable to the business partner, reducing the potential impact of unauthorized access or misuse while still allowing for process auditing.
Requiring data deletion addresses data retention policies but does not mitigate the privacy risk associated with the identifiable information being processed *during* the audit.
Using a secure channel protects the data during transmission but does not mitigate the privacy risk once the business partner has received and is processing the identifiable personal information.
Contractual provisions establish legal obligations but do not technically reduce the inherent privacy risk of sharing identifiable personal information itself; they primarily define responsibilities and liabilities.
Concept tested: Privacy risk mitigation (data obfuscation)
Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/data-masking
Topics
Community Discussion
No community discussion yet for this question.