IIA-CIA-PART2 · Question #320
During a review of data privacy an internal auditor is tasked with testing management's identification and prioritization of critical data collected by the organization. Which of the following steps…
The correct answer is D. Document and test a data inventory and classification program by determining the data. The step that would accomplish the objective of testing management's identification and prioritization of critical data collected by the organization is to document and test a data inventory and classification program by determining the data classification levels and framework…
Question
During a review of data privacy an internal auditor is tasked with testing management's identification and prioritization of critical data collected by the organization. Which of the following steps would accomplish this objective?
Options
- Ainterview management to determine what types of data are collected and maintained
- BTrace data from storage to the collection sources to determine how critical data is collected and
- CReview a sample of data to determine whether the risk classification is reasonable
- DDocument and test a data inventory and classification program by determining the data
How the community answered
(49 responses)- A16% (8)
- B6% (3)
- C4% (2)
- D73% (36)
Explanation
The step that would accomplish the objective of testing management's identification and prioritization of critical data collected by the organization is to document and test a data inventory and classification program by determining the data classification levels and framework. This involves verifying that management has established a comprehensive data inventory and that data classification processes are in place and effectively implemented. It ensures that data is appropriately categorized based on its criticality and sensitivity, aligning with the organization's risk management framework and data governance policies.
Topics
Community Discussion
No community discussion yet for this question.