Question 1 of 30
Globex Enterprises, a multinational corporation with operations in the EU, US, and Asia, is undergoing a major overhaul of its customer relationship management (CRM) system. This new system will consolidate customer data from various regional databases into a single, globally accessible platform. Globex is certified to ISO 27001:2013 and is now seeking to implement ISO 27701:2019 to enhance its privacy information management system (PIMS). The Chief Information Security Officer (CISO), Anya Sharma, is tasked with ensuring the new CRM system aligns with ISO 27701:2019 principles, particularly regarding data protection by design and by default. Considering the global reach of Globex and the sensitivity of customer data, what is the MOST comprehensive approach Anya should take to ensure the new CRM system adheres to ISO 27701:2019 requirements during this system upgrade?
Conduct Privacy Impact Assessments (PIAs) during the design phase of the new CRM system, incorporate privacy-enhancing technologies (PETs) where feasible, establish default privacy settings aligned with GDPR and other relevant regulations, and implement comprehensive training and awareness programs for all personnel involved in the system's operation.
Primarily focus on updating the existing ISO 27001:2013 documentation and security policies to include references to privacy requirements, and ensure that the existing security controls are applied to the new CRM system.
Concentrate on developing a robust data breach management plan that outlines procedures for identifying, reporting, and mitigating data breaches in the new CRM system, ensuring compliance with notification requirements under GDPR and other relevant laws.
Delegate the responsibility of ensuring privacy compliance to the legal department and rely on their expertise to review the system's design and implementation after it has been developed, making adjustments as necessary to comply with relevant privacy laws.

Preparing for ISO 14044:2006 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free