nerdexam
Isaca

AAISM · Question #142

Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?

The correct answer is C. Establish policies and awareness training for acceptable AI use. Establishing policies and conducting awareness training for acceptable AI use is the most effective organizational control because it directly governs how employees interact with generative AI tools - preventing inadvertent exposure of sensitive data through prompts or uploads…

AI Security Strategy and Governance

Question

Which of the following is the MOST effective action an organization can take to address data security risk when using generative AI features in an application?

Options

  • AEstablish IP ownership guidelines with third parties
  • BRequire opt-out provisions for data usage
  • CEstablish policies and awareness training for acceptable AI use
  • DRely on the AI provider's independent audit reports

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    78% (28)
  • D
    3% (1)

Explanation

Establishing policies and conducting awareness training for acceptable AI use is the most effective organizational control because it directly governs how employees interact with generative AI tools - preventing inadvertent exposure of sensitive data through prompts or uploads. IP ownership guidelines (A) address legal concerns, not data security. Opt-out provisions (B) are a compliance mechanism, not a primary security control. Relying solely on a provider's audit reports (D) is a passive, third-party-dependent approach that does not control internal employee behavior, which is the primary vector for data exposure.

Topics

#AI security policies#Security awareness training#Generative AI risk management#Data security governance

Community Discussion

No community discussion yet for this question.

Full AAISM Practice