Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP Exam CIPM Topic 10 Question 76 Discussion

Actual exam question for IAPP's CIPM exam
Question #: 76
Topic #: 10
[All CIPM Questions]

Which of the following controls does the PCI DSS framework NOT require?

Show Suggested Answer Hide Answer
Suggested Answer: A

The optimum first step to take when creating a Privacy Officer governance model is to involve senior leadership. Senior leadership plays a crucial role in establishing and supporting a privacy program within an organization. They can provide strategic direction, allocate resources, approve policies, endorse initiatives, communicate values, and demonstrate accountability. By involving senior leadership from the beginning, a Privacy Officer can ensure that the privacy program aligns with the organization's vision, mission, goals, and culture. Senior leadership can also help overcome potential barriers or resistance from other stakeholders by endorsing and promoting the privacy program.


CIPM Body of Knowledge (2021), Domain I: Privacy Program Governance, Section A: Privacy Governance Models, Subsection 1: Privacy Officer Governance Model

CIPM Study Guide (2021), Chapter 2: Privacy Governance Models, Section 2.1: Privacy Officer Governance Model

CIPM Textbook (2019), Chapter 2: Privacy Governance Models, Section 2.1: Privacy Officer Governance Model

CIPM Practice Exam (2021), Question 139

Contribute your Thoughts:

Jesus
1 days ago
I see your point, but I still think it's A) Implement strong asset control protocols because it's not explicitly mentioned in the PCI DSS framework.
upvoted 0 times
...
Lashanda
2 days ago
I was sure it was C. A security policy is like the backbone of PCI DSS, how could that not be required?
upvoted 0 times
...
Bok
3 days ago
I disagree, I believe the answer is C) Maintain an information security policy.
upvoted 0 times
...
Carma
9 days ago
Hmm, this one's tricky. PCI DSS covers a lot of ground, but I think the answer might be A. Asset control isn't specifically mentioned in the standard.
upvoted 0 times
...
Jesus
10 days ago
I think the answer is A) Implement strong asset control protocols.
upvoted 0 times
...

Save Cancel