Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?
Haha, D is a classic trap answer. Fiduciary responsibility for credit cards? That's way too specific. The main reason has to be one of the broader, more general options.
I was thinking B - transferring the risk. If you can't eliminate the risk of handling PII, you need to at least shift it to someone else, like an insurance provider.
Yeah, I agree with Mary. Compliance and risk transfer are important, but really understanding the risks is key. You can't manage what you don't understand.
I think the main reason is C - we need to better understand the risks associated with using PII data. That's critical for any organization handling sensitive information.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Jordan
13 days agoHassie
1 days agoMona
19 days agoMoon
1 months agoTheodora
1 months agoSolange
1 months agoLawrence
1 months agoLenna
15 days agoCaprice
1 months ago