🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer114 / 147
Question 114 of 147

A newly appointed privacy officer at a financial services firm is establishing the privacy risk management program. During a workshop, the executive team asks how they should decide which identified privacy risks require formal treatment plans versus which can proceed without additional action. The privacy officer wants to give the organization a consistent, board-endorsed basis for making these decisions across all business units. What should the privacy officer establish FIRST to enable this?

Reviewed for accuracy · Report an issueNext question