An organization plans to deploy Wi-Fi location analytics to count the number of shoppers per day across its various retail outlets.
What should the IS auditor recommend as the FIRST course of action by IT management?
Click on the arrows to vote for the correct answer
A. B. C. D.A.
The best course of action for IT management when deploying Wi-Fi location analytics to count the number of shoppers per day across its various retail outlets is to conduct a privacy impact assessment (PIA). Therefore, option A is the correct answer.
Explanation:
A privacy impact assessment (PIA) is a risk management process used to identify and assess the privacy risks associated with a particular project or system. In this case, deploying Wi-Fi location analytics to count the number of shoppers per day across various retail outlets may involve collecting personal information such as MAC addresses or other identifying information. As a result, a PIA will help to identify the potential privacy risks associated with the project and develop mitigation strategies to address them.
Masking Media Access Control (MAC) addresses is also a good security measure as it can prevent unauthorized tracking or identification of devices, but it is not the FIRST course of action. Similarly, surveying shoppers for feedback is a good way to gather information, but it does not address the privacy risks associated with collecting personal information. Developing a privacy notice to be displayed to shoppers is also a good practice, but it is not the FIRST course of action.
Therefore, conducting a privacy impact assessment is the most appropriate and necessary first step for IT management before deploying Wi-Fi location analytics to count the number of shoppers per day across its various retail outlets.