🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor44 / 148
Question 44 of 148
A multinational retailer processes customer personal data in several countries. Its internal data protection policy was written to satisfy the requirements of the country where the corporate headquarters is located. During an audit, the IS auditor finds that one subsidiary operates in a jurisdiction whose privacy law imposes stricter consent and data-transfer requirements than the corporate policy. Which of the following should the auditor recommend as the MOST appropriate course of action?
Reviewed for accuracy · Report an issueNext question