QUESTION IMAGE
Question
which risk remains after additional controls are applied?
inherent risk
residual risk
control risk
internal risk
10 pts
question 10
after reviewing the data collection procedures in your organization, a court ordered you to issue a document that specifies how the organization uses the collected personal information. this document must be displayed to the user before allowing them to share personal data. which of the following documents should you prepare?
privacy notice
terms of agreement
data minimization
pseudo - anonymization
Brief Explanations
- For the first question, residual risk is the risk that remains after all controls and risk - mitigation efforts have been applied. Inherent risk exists before controls, control risk relates to the failure of internal controls, and 'internal risk' is not a standard risk term in this context.
- For the second question, a privacy notice is a document that specifies how an organization uses collected personal information and is typically shown to users before they share personal data. Terms of agreement cover broader contractual terms, data minimization is a principle, and pseudo - anonymization is a data - processing technique.
Snap & solve any problem in the app
Get step-by-step solutions on Sovi AI
Photo-based solutions with guided steps
Explore more problems and detailed explanations
- First question: B. Residual risk
- Second question: A. Privacy notice