CAS-001 · Question #153
A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in…
The correct answer is A. Provide targeted security awareness training and impose termination for repeat violators. This incident is fundamentally a human behavior and policy compliance issue, not purely a technical one. The manager made a deliberate but misguided decision to circumvent access controls using a legitimate tool (desktop sharing). Option A - targeted security awareness training…
Question
A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in training was to log into the payroll system, and then activate desktop sharing with a trusted subordinate. The manager granted the subordinate control of the desktop thereby giving the subordinate full access to the payroll system. The subordinate did not have authorization to be in the payroll system. Another employee reported the incident to the security team. Which of the following would be the MOST appropriate method for dealing with this issue going forward?
Options
- AProvide targeted security awareness training and impose termination for repeat violators.
- BBlock desktop sharing and web conferencing applications and enable use only with approval.
- CActively monitor the data traffic for each employee using desktop sharing or web conferencing applications.
- DPermanently block desktop sharing and web conferencing applications and do not allow its use at the
How the community answered
(23 responses)- A96% (22)
- C4% (1)
Explanation
This incident is fundamentally a human behavior and policy compliance issue, not purely a technical one. The manager made a deliberate but misguided decision to circumvent access controls using a legitimate tool (desktop sharing). Option A - targeted security awareness training with consequences for repeat violations - addresses the root cause: the manager did not understand or appreciate the security and compliance implications of sharing access to a sensitive system like payroll. Training reinforces proper behavior, and the threat of termination for repeat violations creates accountability. Option D (permanently blocking the tool) is overly restrictive and eliminates legitimate business use. Option B (block with approval) may be too restrictive and does not address the awareness gap. Option C (active monitoring) is reactive and does not prevent the behavior. A balanced, educational-first approach with escalating consequences best fits a first-time policy violation of this nature.
Topics
Community Discussion
No community discussion yet for this question.