ISFS · Question #24
What is the best way to comply with legislation and regulations for personal data protection?
The correct answer is D. Appointing the responsibility to someone. Appointing responsibility to a designated person (such as a Data Protection Officer) is the foundational compliance requirement under data protection laws like GDPR, which explicitly mandates organizational accountability through role assignment - without someone accountable…
Question
What is the best way to comply with legislation and regulations for personal data protection?
Options
- APerforming a threat analysis
- BMaintaining an incident register
- CPerforming a vulnerability analysis
- DAppointing the responsibility to someone
How the community answered
(23 responses)- A4% (1)
- B13% (3)
- D83% (19)
Explanation
Appointing responsibility to a designated person (such as a Data Protection Officer) is the foundational compliance requirement under data protection laws like GDPR, which explicitly mandates organizational accountability through role assignment - without someone accountable, no other measures can be systematically enforced. Threat analysis (A) is a security risk activity, not a legal compliance mechanism. Vulnerability analysis (C) is a technical security practice focused on system weaknesses, not regulatory obligations. Maintaining an incident register (B) supports compliance after breaches occur but is a reactive measure, not the primary compliance approach - and it only works if someone is already responsible for it.
Memory tip: Think "legislation = accountability = a person." Laws assign responsibility to organizations, so organizations must assign responsibility to a person. The other options are security/operational practices that support compliance but don't fulfill the legal obligation of organizational accountability.
Topics
Community Discussion
No community discussion yet for this question.