Question 1 of 30
Consider AstroNova Dynamics, a company preparing to launch a new data-intensive service in a burgeoning international market. Simultaneously, a new, stringent data privacy regulation, the \"Global Data Integrity Act\" (GDIA), is enacted, directly impacting their core customer relationship management (CRM) system. As the Lead Implementer for ISO 31010:2019, how should you strategically adapt the organization\'s risk management approach to address both the immediate regulatory challenge and the long-term market expansion goal, ensuring effective integration rather than parallel, potentially conflicting, processes?
Prioritize risk treatments addressing critical GDIA compliance gaps for the CRM system and concurrently develop a data governance framework that supports both compliance and the new market strategy.
Focus exclusively on the GDIA's prescriptive requirements for the CRM system, deferring any strategic integration of data governance until after the initial compliance deadline.
Implement a completely new risk assessment methodology specifically for the GDIA that runs parallel to the existing ISO 31000 framework, creating redundant processes.
Relegate the GDIA compliance solely to the IT department, assuming it is purely a technical issue and not requiring broader organizational risk oversight.