Question 1 of 30
TechForward Solutions, an ISO 27001 certified organization based in the US, is implementing a new cloud-based CRM system to better manage its customer relationships. This CRM will handle a significant volume of personal data belonging to EU citizens. The Chief Information Security Officer (CISO) is tasked with ensuring that the implementation aligns with both ISO 27001 and relevant privacy regulations, particularly GDPR, using ISO 27701 as a guide. TechForward wants to leverage its existing ISO 27001 certification to streamline the process. Which of the following actions represents the MOST comprehensive approach to integrating privacy considerations and complying with relevant regulations during the CRM implementation?
Conduct a Privacy Impact Assessment (PIA) for the new CRM system, update the Statement of Applicability (SoA) to include relevant ISO 27701 controls, and establish processes for managing data subject rights under GDPR.
Extend the existing ISO 27001 certification to cover the new CRM system by adding a clause in the contract with the CRM vendor stating their compliance with GDPR and ISO 27701.
Rely solely on the CRM vendor's compliance documentation and certifications, assuming that their adherence to GDPR and ISO 27701 sufficiently covers TechForward's obligations.
Conduct a general security audit of the CRM system focusing primarily on network security and access controls, without specifically addressing privacy risks or data subject rights.

Preparing for ISO 39001:2012 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free