Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?
Haha, D is a classic trap answer. Fiduciary responsibility for credit cards? That's way too specific. The main reason has to be one of the broader, more general options.
Haha, D is a classic trap answer. Fiduciary responsibility for credit cards? That's way too specific. The main reason has to be one of the broader, more general options.
I was thinking B - transferring the risk. If you can't eliminate the risk of handling PII, you need to at least shift it to someone else, like an insurance provider.
Yeah, I agree with Mary. Compliance and risk transfer are important, but really understanding the risks is key. You can't manage what you don't understand.
I think the main reason is C - we need to better understand the risks associated with using PII data. That's critical for any organization handling sensitive information.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Jordan
22 days agoBrett
1 days agoAshley
3 days agoHassie
10 days agoMona
28 days agoMerlyn
3 days agoMoon
1 months agoTheodora
1 months agoSolange
2 months agoLawrence
2 months agoLenna
24 days agoCaprice
2 months ago