CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 276


A new regulation in one country of a global organization has recently prohibited cross-border transfer of personal data. An IS auditor has been asked to determine the organization's level of exposure in the affected country. Which of the following would be MOST helpful in making this assessment?

Show Answer
Correct Answer: CD

To determine the organization's level of exposure to the new regulation prohibiting cross-border transfer of personal data, it is most helpful to identify business processes associated with personal data exchange with the affected jurisdiction. By understanding these processes, an IS auditor can assess how the regulation impacts the organization’s operations and pinpoint areas that require immediate attention or compliance measures. This assessment ensures a targeted and effective response to the regulation.

Discussion

8 comments
Sign in to comment
007GeorgeoOption: C
May 5, 2023

C for sure

oldmagicOption: C
Jun 26, 2023

C is the correct answer for me. You have to identify the business process before you can identify the entities

saado9Option: C
Apr 19, 2023

C. Identifying business processes associated with personal data exchange with the affected jurisdiction

3008Option: C
Apr 30, 2023

c is answer

3008
Jun 12, 2023

SORRY , C IS NOT ANSWER

3008Option: D
Jun 12, 2023

the most helpful in making an assessment of the organization's level of exposure to the new regulation. However, the IS auditor may need to undertake additional activities such as reviewing data classification procedures and identifying data security threats to provide a comprehensive assessment.

3008
Jul 30, 2023

Option C - Identifying business processes associated with personal data exchange with the affected jurisdiction This option involves identifying business processes that involve the exchange of personal data with the affected jurisdiction. It is an important activity as it provides insight into the organization's exposure to the new regulation. By identifying these processes, the IS auditor can assess the potential impact of the new regulation on the organization's operations. Option D - Developing an inventory of all business entities that exchange personal data with the affected jurisdiction This option involves creating a list of all business entities that exchange personal data with the affected jurisdiction. This option is the most helpful in assessing the organization's level of exposure to the new regulation as it provides a comprehensive overview of all the organization's operations that are impacted. The IS auditor can use this list to identify critical business processes and prioritize the organization's compliance efforts.

echo_cert
Mar 9, 2024

C is correct, sorry. It's not the responsibility of an Auditor to develop an inventory. Auditors review, identify, observe etc. But not perform an operational task.

blues_leeOption: C
Jan 30, 2024

C is the correct answer for me.

Yejide03Option: C
Jan 31, 2024

Identifying business processes

analuisamoreiraOption: C
Jun 27, 2024

Question is about "most helpful", in my opinion is more important to understand the business impact, although it's is important to have an inventory. I think D would come first, but C is more relevant.