A company processes and stores sensitive data on its own systems. Which of the following steps should the company take first to ensure compliance with privacy regulations?
Choose an answer
Tap an option to check your answer.
Correct answer: Implement access controls and encryption..
Why this is the answer
To ensure compliance with privacy regulations, the first step is to implement access controls and encryption. These foundational security measures directly address the core requirements of most privacy regulations by limiting who can access sensitive data and protecting it from unauthorized disclosure, even if accessed. Without these in place, other efforts are less effective. Developing and providing training on data protection policies is crucial but follows the establishment of technical controls. Creating incident response and disaster recovery plans is essential for managing breaches and outages, but these are reactive or recovery measures, not primary preventative controls. Purchasing and installing security software is a general step, but "access controls and encryption" are specific, critical functions that such software would perform, making the correct answer more precise and fundamental.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed