Study. uk . com
  1. Home
  2. All questions
  3. Question 17

CISM study material · question 17 of 1000

A privacy officer argues that if the organisation prevents all security incidents, it will have no privacy risk. How should the security manager respond, consistent with CSF 2.0?

  1. Privacy risk applies only to personal data a regulator has named, so processing outside that scope raises no privacy concern of its own
  2. Privacy and security risk are identical and managed by one process
  3. Privacy problems can arise from ordinary authorised data processing with no security incident involved
  4. Privacy risk is a strict subset of security risk, so the claim is correct
Show the answer

Answer: C. Privacy problems can arise from ordinary authorised data processing with no security incident involved

CSF notes that cybersecurity risk management addresses privacy risks arising from loss of confidentiality, integrity or availability, but privacy risks can also arise from authorised data processing unrelated to any incident.

Source: NIST CSWP 29 (NIST) — Sec. 5.2 Improving Integration

Challenge yourself on this topic → Study as cards