ETExamTower
Q4Fundamentals

Under the GDPR, what action should be taken with data to ensure its confidentiality, integrity, and availability?

← → navigate · a answer
Community votes
B
100% (4)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 5
B 2
Selected Answer: B DPIA is the KEY term for GDPR and the related risk around processing.
B 1
Selected Answer: B B, but it could also be C, why not?
1
C. https://www.itgovernance.co.uk/green-papers/penetration-testing-and-the-gdpr
1
According to GDPR, to keep the confidentiality, integrity, and availability of data, the following steps should be taken: A. Perform a vulnerability assessment. A vulnerability assessment is the process of finding and evaluating security vulnerabilities in an organization's information systems, applications, and network infrastructure. By carrying out a vulnerability assessment, an organization can identify possible security weaknesses and take the appropriate action to mitigate or eliminate them. This is essential to ensuring the confidentiality, integrity, and availability of data. While conducting a data protection impact assessment, penetration testing, and awareness testing are also important parts of a comprehensive data security strategy, they are not specifically mentioned in GDPR as measures to ensure the confidentiality, integrity, and availability of data.
B 1
Selected Answer: B Under GDPR, keeping the confidentiality, integrity, and availability of personal data is done through risk assessment and the right safeguards. The main formal mechanism GDPR defines for this is the Data Protection Impact Assessment (DPIA).