CASE STUDY
Please use the following to answer the next question:
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
When prioritizing the updates to its policies, rules and procedures to include the new AI system for user authentication, the organization should:
- Update third-party data sharing policies.
- Update security controls for sensitive data.
- Ensure that any personal data used is only processed for a specific and lawful purpose.
- Reduce the complexity of the policy to make it easier for non-technical employees to understand.
Answer(s): C
Explanation:
Since the AI system processes personal behavioral data (typing patterns) for authentication, the organization must ensure that this personal data is processed only for specific and lawful purposes, aligning with data protection principles.
Show Answer Next Question