モノのインターネット (IoT) デバイスを使用して個人を特定できる情報 (PII) を収集および処理するリスクを評価する際に、主に考慮すべき事項は次のどれですか。
正解:D
Local laws and regulations should be the primary consideration when assessing the risk of using IoT devices to collect and process PII, because they define the legal obligations and liabilities of the organization and the individuals involved. Non-compliance with local laws and regulations can result in fines, lawsuits, reputational damage, and loss of trust. Therefore, it is essential to understand and adhere to the applicable laws and regulations in the jurisdictions where the IoT devices operate and where the PII is stored, processed, and transferred.
References
*Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks
*The Internet of Things (IoT) and Digitally Stored PII: Avoidable or Inevitable?
*Security Issues in IoT: Challenges and Countermeasures