Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CDPSE All Questions

View all questions & answers for the CDPSE exam

Exam CDPSE topic 1 question 233 discussion

Actual exam question from Isaca's CDPSE
Question #: 233
Topic #: 1
[All CDPSE Questions]

Which of the following should be reviewed FIRST as part of an audit of controls implemented to mitigate data privacy risk?

  • A. Privacy impact assessment (PIA)
  • B. Security impact assessment
  • C. Privacy policies and procedures
  • D. Privacy risk and control framework
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
821bbab
1 month ago
Answer is D. The privacy risk and control framework is the most appropriate starting point for an audit of controls implemented to mitigate data privacy risk. This framework outlines the overall strategy for identifying, assessing, and managing privacy risks, as well as the controls put in place to address those risks. Reviewing it first provides auditors with an understanding of the organization's approach to privacy risk management, enabling them to assess whether the implemented controls align with identified risks and legal requirements. Privacy impact assessment (PIA): While important, a PIA focuses on specific projects or data processing activities. It should be reviewed as part of the audit, but the overarching privacy risk and control framework provides a more comprehensive starting point.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...