- Home
- All questions
- Question 17
CISM study material · question 17 of 1000
A privacy officer argues that if the organisation prevents all security incidents, it will have no privacy risk. How should the security manager respond, consistent with CSF 2.0?
Show the answer
Answer: C. Privacy problems can arise from ordinary authorised data processing with no security incident involved
CSF notes that cybersecurity risk management addresses privacy risks arising from loss of confidentiality, integrity or availability, but privacy risks can also arise from authorised data processing unrelated to any incident.
Source: NIST CSWP 29 (NIST) — Sec. 5.2 Improving Integration