CISA Protection of Information Assets Practice Question
During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?
⚠ Common exam trap
CISA often tests regulation-to-requirement mapping, and the trap is confusing HIPAA's 'Privacy Officer' or PCI DSS's security controls with GDPR's specific DPO mandate—candidates who see 'privacy' and jump to HIPAA or PCI DSS miss the EU-resident trigger.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GDPR
The GDPR (EU Regulation 2016/679) governs the processing of personal data of EU residents and mandates the appointment of a Data Protection Officer (DPO) in specific circumstances—such as large-scale systematic monitoring or large-scale processing of special categories of data by public authorities or core-activity organizations. Processing EU residents' personal data without a required DPO is a direct GDPR Article 37 violation. The other regulations listed address payment card data, financial reporting integrity, and US healthcare information, none of which impose a DPO requirement for EU personal data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PCI DSS
Why it's wrong here
PCI DSS governs payment card data security, not EU personal data processing or DPO appointment, so it cannot be the regulation breached here. It is tempting because PCI DSS also mandates privacy-adjacent controls, but it would be the correct framework only when cardholder data is stored, processed or transmitted.
- ✗
SOX
Why it's wrong here
SOX governs financial reporting controls for US-listed companies, not EU personal data processing or DPO appointment. It is tempting because SOX also requires documented internal controls, but it would be the correct framework only when auditing financial statement integrity and disclosure controls for public companies.
- ✗
HIPAA
Why it's wrong here
HIPAA applies to protected health information in the United States, not to EU residents' personal data or DPO obligations. It is tempting because HIPAA also imposes privacy and security safeguards, but it would be the correct regulation only for US healthcare covered entities and business associates handling PHI.
- ✓
GDPR
Why this is correct
GDPR mandates a DPO for public authorities and for processing requiring large-scale, regular and systematic monitoring or special-category data. Processing EU residents' personal data without an appointed DPO breaches that obligation, whereas other privacy regulations impose no equivalent universal DPO requirement.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.