CIA-2 - Engagement Planning - Section A.3

Plan the engagement to assess key risks and controls, recognizing strategic objectives, cybersecurity and IT control concepts, business continuity, finance and accounting concepts, and common business-process risks and controls.

Plan an engagement around the strategic objectives of the activity under review and their integration with risk management, while recognising cybersecurity risks, IT general controls, and data privacy practices relevant to the area. Factor in business continuity and disaster recovery, core finance and accounting concepts such as assets, liabilities, and capital, and the key risks and controls typical of common business processes including procurement, inventory, accounts payable, and ERP or CRM systems.

IT general controlsBusiness continuityBusiness process riskData privacy

Practice question for this objective

Free sampleEngagement Planninghard

An auditor is scoping an engagement over a customer relationship system that stores personal data. To frame the data privacy risk correctly for planning, which statement best captures the core data privacy concept the auditor should apply?

  • APersonal data should be collected and processed only for specified, legitimate purposes and limited to what those purposes require. Correct
  • BPersonal data should be encrypted at rest and in transit so that a network intruder who intercepts it cannot read the contents.
  • CPersonal data should be retained indefinitely so that the organisation can always respond to any future regulator or customer request.
  • DPersonal data should be made available across all internal departments to maximise the business value the organisation extracts from it.
Apply purpose limitation and data minimisation as the core data privacy principles when scoping a privacy risk during planning. Data privacy centres on collecting and processing personal data only for specified legitimate purposes and only to the extent those purposes require. Encryption addresses security, and broad retention or sharing raises exposure, so purpose limitation and minimisation are the concepts the auditor should apply when framing the risk.

Why A is correct: Correct because purpose limitation and data minimisation are foundational privacy principles, so the auditor frames the risk around whether collection and use stay within the stated legitimate purpose.

Why B is wrong: Tempting because encryption protects data, but it is a security safeguard supporting confidentiality rather than the privacy principle governing why and how much personal data may be collected and used.

Why C is wrong: Tempting because retention supports responsiveness, but indefinite retention conflicts with storage limitation and increases privacy exposure, so it misstates the underlying privacy concept.

Why D is wrong: Tempting because data sharing can create value, but broad internal availability conflicts with access restriction and purpose limitation, increasing rather than controlling privacy risk.

See more CIA-2 practice questions, answers explained.

More in this domain

Back to all Engagement Planning objectives, or the CIA-2 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.