CIPM Exam QuestionsBrowse all questions from this exam

CIPM Exam - Question 102


SCENARIO -

Please use the following to answer the next question:

As they company’s new chief executive officer, Thomas Goddard wants to be known as a leader in data protection. Goddard recently served as the chief financial officer of Hoopy.com, a pioneer in online video viewing with millions of users around the world. Unfortunately, Hoopy is infamous within privacy protection circles for its ethically questionable practices, including unauthorized sales of personal data to marketers. Hoopy also was the target of credit card data theft that made headlines around the world, as at least two million credit card numbers were thought to have been pilfered despite the company’s claims that “appropriate” data protection safeguards were in place. The scandal affected the company’s business as competitors were quick to market an increased level of protection while offering similar entertainment and media content. Within three weeks after the scandal broke, Hoopy founder and CEO Maxwell Martin, Goddard’s mentor, was forced to step down.

Goddard, however, seems to have landed on his feet, securing the CEO position at your company, Medialite, which is just emerging from its start-up phase. He sold the company’s board and investors on his vision of Medialite building its brand partly on the basis of industry-leading data protection standards and procedures. He may have been a key part of a lapsed or even rogue organization in matters of privacy but now he claims to be reformed and a true believer in privacy protection. In his first week on the job, he calls you into his office and explains that your primary work responsibility is to bring his vision for privacy to life. But you also detect some reservations. “We want Medialite to have absolutely the highest standards,” he says. “In fact, I want us to be able to say that we are the clear industry leader in privacy and data protection. However, I also need to be a responsible steward of the company’s finances. So, while I want the best solutions across the board, they also need to be cost effective.”

You are told to report back in a week’s time with your recommendations. Charged with this ambiguous mission, you depart the executive suite, already considering your next steps.

The company has achieved a level of privacy protection that established new best practices for the industry. What is a logical next step to help ensure a high level of protection?

Show Answer
Correct Answer: C

Focusing on improving the incident response plan is a logical next step to help ensure a high level of protection for the company. A robust incident response plan will better prepare the organization to effectively respond to any potential breaches or breaks in data protection. This includes having a well-defined and tested plan, clear roles and responsibilities, established communication channels, and conducting regular drills and simulations. This proactive approach enhances the organization's ability to detect, respond to, and recover from any privacy incidents, thereby maintaining their high standards of data protection.

Discussion

4 comments
Sign in to comment
CockOption: C
Oct 20, 2023

By focusing on improving the incident response plan, the company can better prepare and respond in the event of any breaks in protection. This includes having a well-defined and tested plan in place, ensuring clear roles and responsibilities, establishing communication channels, and conducting regular drills and simulations to enhance the organization's ability to detect, respond to, and recover from any privacy incidents.

ET1857Option: C
Nov 7, 2023

Improving on incident response plan should be the focus rather shifting the focus on new technologies because the program is mature enough to do due diligence before onboarding any new product for privacy impacts.

SsouravOption: D
Sep 14, 2023

D. Shift attention to privacy for emerging technologies as the company begins to use them. Emerging technologies can introduce new and unforeseen privacy challenges. By proactively addressing privacy concerns in these areas, the company will be ahead of potential issues and continue to be an industry leader in privacy protection. It ensures that as the company adopts new technologies, they maintain their high standard of privacy protection.

carlosbuiOption: B
Dec 1, 2023

should be B