問題文
A security team argues that a system holding personal data has no privacy risk because it has no known vulnerabilities and no breach has occurred. Which explanation corrects that reasoning?
選択肢
- Privacy risk is the same as compliance risk, so an absence of findings in the last audit is sufficient evidence.
- Privacy risk exists only where a legal requirement applies, so the assessment should start from the applicable law rather than from the system.
- Privacy risk can arise from the authorized processing itself, so a system with no security weakness can still create risk through what it does with the data.
- Privacy risk equals security risk multiplied by the record count, so a system with no vulnerability still carries a residual amount.