Question 22
Domain 6: Sustaining Privacy Program PerformanceA privacy professional is assembling documentation to demonstrate ongoing accountability for a privacy program. Which set of materials best prepares evidence of governance?
Correct answer: B
Explanation
Evidence of governance should document how the program is directed, what decisions were made, which controls are in place, and the current status of remediation activities. — Prepare evidence of governance, decisions, controls and remediation status.
Why each option is right or wrong
A. Training records, vendor invoices, marketing plans, and office seating charts
Evidence should cover governance, decisions, controls, and remediation status rather than general administrative records.
B. Governance records, decision logs, control documentation, and remediation status updates
The source states that evidence of governance should include governance, decisions, controls, and remediation status. This set matches all four required categories for demonstrating ongoing accountability.
C. Incident statistics, employee surveys, budget forecasts, and project charters
Incident data alone does not satisfy the need to document governance, decisions, controls, and remediation status.
D. Policy drafts, system architecture diagrams, audit schedules, and customer complaints
Evidence must specifically include decisions and remediation status, not just related program artifacts.