CISA Certified Information Systems Auditor – Question2683

An organization globally distributes a free phone application that includes a module to gather and report user information. The application includes a privacy notice alerting users to the data gathering. Which of the following presents the GREATEST risk?

A.
The data gathering notice is available in only one language.
B. There is no framework to delete personal data.
C. There may be a backlash among users when the data gathering is revealed.
D. The data is not properly encrypted on the application server.

Correct Answer: D