nerdexam
Isaca

AAISM · Question #107

An organization has discovered that employees have started regularly utilizing open-source generative AI without formal guidance. Which of the following should be the CISO's GREATEST concern?

The correct answer is C. Data leakage. The greatest immediate risk from unsanctioned use of public or open-source generative AI tools is data leakage--employees may paste confidential or regulated information into third-party systems, resulting in loss of confidentiality, regulatory exposure, and loss of…

AI Security Risk Management

Question

An organization has discovered that employees have started regularly utilizing open-source generative AI without formal guidance. Which of the following should be the CISO's GREATEST concern?

Options

  • ALack of monitoring
  • BPolicy violations
  • CData leakage
  • DModel hallucinations

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    21% (8)
  • C
    61% (23)
  • D
    13% (5)

Explanation

The greatest immediate risk from unsanctioned use of public or open-source generative AI tools is data leakage--employees may paste confidential or regulated information into third-party systems, resulting in loss of confidentiality, regulatory exposure, and loss of intellectual property. AAISM emphasizes that when AI use occurs outside approved channels, the top control priority is preventing exfiltration of sensitive data via prompts, attachments, and context sharing. Monitoring and policy are necessary enablers, but leakage is the highest-impact failure mode in the short term; hallucinations primarily affect accuracy, not confidentiality.

Topics

#Data leakage#Generative AI security#Unsanctioned AI use#Risk prioritization

Community Discussion

No community discussion yet for this question.

Full AAISM Practice