Question 7
Domain 1: Privacy Program Framework and StrategyA privacy leader is drafting the foundation of a new privacy program. Which action best aligns with defining the program purpose and outcomes at this stage?
Correct answer: B
Explanation
At the outset of a privacy program, leaders should clearly state the program’s purpose, its objectives, and the business outcomes it is intended to achieve. These elements establish why the program exists, what it aims to do, and how success will be expressed for the organization. — Define the program’s purpose, objectives and desired business outcomes.
Why each option is right or wrong
A. Document the program’s technical controls and vendor configurations
Purpose and outcomes are defined before detailing technical controls or vendor configurations.
B. Define the program’s purpose, objectives, and desired business outcomes
The source states that this stage of privacy program development is to define the program’s purpose, objectives, and desired business outcomes, which directly matches the action described in the scenario.
C. Assign disciplinary measures for future privacy policy violations
Program definition focuses on purpose, objectives, and business outcomes, not enforcement measures.
D. List all operational tasks that privacy staff may eventually perform
Objectives and business outcomes come before compiling a full inventory of operational tasks.