ある組織が給与計算システムを SaaS (Software as a Service) アプリケーションに移行しました。新しいデータ プライバシー規制では、データは収集された国内でのみ処理できると規定されています。この状況に対処するには、次のどれを最初に行う必要がありますか?
正解:B
The first step when addressing the situation of moving the payroll system to a SaaS application and complying with the new data privacy regulation is to understand the data flows. This means identifying where the data is collected, stored, processed, and transferred, and who has access to it. Understanding the data flows can help to determine the scope and impact of the regulation, as well as the potential risks and gaps in the current state. It can also help to identify the roles and responsibilities of the organization and the SaaS provider regarding data protection and compliance. References = Risk and Information Systems Control Study Manual, Chapter 5, Section 5.3.1.2, p. 237-238