Exam IIA-CIA-Part2 All QuestionsBrowse all questions from this exam
Question 102

Which of the following items should be addressed in an organization's privacy statement?

I. Intended use of collected information.

II. Data storage and security.

III. Network/infrastructure authentication controls.

IV. Data retention policy of the organization.

Parties authorized to access information.

    Correct Answer: C

    An organization's privacy statement should address the following items: the intended use of collected information, data storage and security, and parties authorized to access information. These aspects are crucial for informing users about how their data will be handled and protected. Data retention policies, while important, are usually detailed in separate policy documents rather than in the privacy statement itself. Network/infrastructure authentication controls are generally part of internal security measures and not typically included in a public privacy statement.

Discussion
Brad626Option: B

Why isn't IV included ??

wiseminosse

maybe because the retention policy is imposed by external legislation

John1237

Option 4 is a separate document (a policy, not a statement).

KonradKOption: D

Can someone explain to me the rationale for C? I think D should be the right one. Anyone has a good explanation?

John1237

What I have concluded is that these aspects can be analyzed during an audit engagement, but not in an organization's privacy statement.

John1237

Security vs Privacy Audits

POKLA

error on the numbering of options

CESSA

Parties authorized to access information. - Refers to item V