Which of the following is the BEST way for an organization to limit potential data exposure when implementing a new application?
Which of the following is the BEST way for an organization to limit potential data exposure when implementing a new application?
A . Implement a data loss prevention (DLP) system.
B . Use only the data required by the application.
C . Encrypt all data used by the application.
D . Capture the application’s authentication logs.
Answer: B
Explanation:
The principle of data minimization states that personal data should be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. By using only the data required by the application, the organization can reduce the amount of data that is collected, stored, processed and potentially exposed. This can also help the organization comply with privacy laws and regulations that require data minimization, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
Reference: CDPSE Review Manual, 2021 Edition, ISACA, page 98
[Data minimization], European Commission
Latest CDPSE Dumps Valid Version with 120 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund