Which of the following is a PRIMARY objective of performing a privacy impact assessment (PIA) prior to onboarding a new Software as a Service (SaaS) provider for a customer relationship management (CRM) system?
A.
To identify controls to mitigate data privacy risks
B.
To classify personal data according to the data classification scheme
C.
To assess the risk associated with personal data usage
D.
To determine the service provider’s ability to maintain data protection controls
Going with C on this one. The primary objective of a PIA is to assess the risk associated with personal data usage and once those risks are identified, the next step is to determine and implement appropriate controls to mitigate those risks (option A). In other words, risk assessment comes first, and based on the results of that assessment, appropriate controls are then selected and implemented.
Its not just the risk with data usage but the entire data flow.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
4dfe785
2 months, 1 week agoARaghunanan
7 months, 3 weeks ago