Question 1 of 30
NovaTech Solutions, a multinational corporation specializing in AI-driven cybersecurity tools, obtained ISO 27001:2022 certification six months ago. Their Information Security Management System (ISMS) was meticulously designed, incorporating a comprehensive risk treatment plan based on existing international data privacy regulations and internal vulnerability assessments. This plan included measures like data encryption, access controls, and incident response protocols, all deemed compliant with the then-current legal framework. Recently, a new comprehensive data privacy law, the \"Global Data Protection Act (GDPA),\" was enacted, imposing significantly stricter requirements for data localization, cross-border data transfers, and mandatory breach notifications within a 24-hour timeframe. The GDPA also introduces substantial financial penalties for non-compliance, potentially reaching up to 5% of NovaTech\'s global annual revenue. NovaTech\'s initial risk assessment, while addressing general data privacy concerns, did not anticipate the specific stipulations of the GDPA. Given this scenario, what is the MOST appropriate immediate action NovaTech should take to maintain compliance with ISO 27001:2022 and mitigate the risks associated with the new data privacy law?
Conduct a gap analysis between the existing risk treatment plan and the requirements of the GDPA, update the risk assessment to reflect the new legal landscape, and revise the risk treatment plan to incorporate new or modified controls addressing the identified gaps.
Rely on the existing ISO 27001:2022 certification, assuming that the certification audit already covered all relevant data privacy regulations, and postpone any adjustments to the ISMS until the next scheduled audit.
Immediately halt all cross-border data transfers to ensure compliance with the GDPA's data localization requirements, without conducting a formal gap analysis or updating the risk treatment plan, to avoid potential legal repercussions.
Implement a public relations campaign to demonstrate NovaTech's commitment to data privacy, while simultaneously lobbying government officials to weaken the GDPA's provisions, thereby minimizing the impact on the company's operations.

Preparing for ISO/IEC 27001:2022 - Information Security Management Systems Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free