Hard1 markMultiple Choice
CPA · Question 29 · Area II: Security
Which of the following is a key requirement of the NIST Privacy Framework's 'Control' function?
Which of the following is a key requirement of the NIST Privacy Framework's 'Control' function?
Answer options:
A.
Develop and implement appropriate activities to enable organizations or individuals to manage data processing.
B.
Develop and implement safeguards to protect data.
C.
Develop and implement activities to identify privacy risks.
D.
Develop and implement activities to notify individuals of breaches.
How to approach this question
NIST Privacy Framework functions: Identify, Govern, Control, Communicate, Protect. 'Control' is unique to Privacy (vs Security) and relates to managing how data is used.
Full Answer
A.Develop and implement appropriate activities to enable organizations or individuals to manage data processing.✓ Correct
The Control function in the NIST Privacy Framework focuses on enabling data management, including policies, processes, and technology that allow organizations and individuals to manage privacy risks and data processing preferences.
Common mistakes
Confusing Control (Privacy) with Protect (Security).
Practice the full CPA ISC Practice Exam
82 questions · hints · full answers · grading
More questions from this exam
Q01A CPA is performing a risk assessment for a client that uses a public cloud provider for its core...HardQ02During a walkthrough of a client's change management process, the auditor notes that developers h...HardQ03A service organization provides a real-time transaction processing platform. The service level ag...HardQ04An auditor is reviewing a SQL query used by the finance team to generate a report of all sales tr...HardQ05A healthcare clearinghouse is preparing for a SOC 2® engagement. They utilize a private cloud dep...Hard
Expert