CISA - Governance and Management of IT - Section 2.1

Evaluate privacy programs and principles together with data governance and classification practices.

Define core privacy principles - such as purpose limitation, data minimisation and individual rights - and explain how a privacy programme operationalises them. Evaluate data governance and data classification practices to determine whether sensitive information is identified, labelled and handled appropriately.

privacy programprivacy principlesdata governancedata classification

Practice question for this objective

Free sampleGovernance and Management of IThard

Which statement BEST distinguishes a privacy programme from a data governance programme within an organisation subject to multiple privacy regulations?

  • AA privacy programme operates inside the legal function, while data governance is an information technology programme accountable to the chief information officer for technical metadata catalogues.
  • BA privacy programme is a one-off implementation aligned to a single regulation, while data governance is a continuing programme that maintains a data dictionary and lineage records.
  • CA privacy programme is concerned with protecting confidentiality of all sensitive records, while data governance is concerned with ensuring availability of operational systems to authorised users.
  • DA privacy programme focuses on the lawful handling of personal data and individual rights, while data governance defines accountability, quality and stewardship for all enterprise data assets. Correct
Differentiate the scope of a privacy programme from data governance by purpose, subject matter and the rights or controls each addresses. A privacy programme exists to operationalise legal and ethical obligations for personal data, including lawful basis, transparency and data-subject rights, while data governance defines accountability, stewardship, quality and lifecycle for all enterprise data assets; the two are complementary but address different subject matter and different stakeholder concerns.

Why A is wrong: Reporting lines vary by organisation and are not the defining difference; framing the distinction as departmental ownership misses that both programmes are cross-functional and that privacy obligations cover technical, legal and operational domains.

Why B is wrong: Privacy programmes are continuing, not one-off, and must address overlapping regulations across jurisdictions; presenting privacy as static reflects a common misconception that ignores the need for ongoing monitoring and updates.

Why C is wrong: This conflates privacy with information security confidentiality and reduces data governance to availability; both programmes have broader purposes than these two security attributes and the answer ignores personal data and stewardship.

Why D is correct: This captures the conceptual split that the CISA blueprint draws: the privacy programme is built around personal data lifecycle obligations and data-subject rights, whereas data governance addresses the broader management of data as an enterprise asset across quality, lineage and stewardship.

See more CISA practice questions, answers explained.

More in this domain

Back to all Governance and Management of IT objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.