CAS-002 · Question #324
A security manager has received the following email from the Chief Financial Officer (CFO): "While I am concerned about the security of the proprietary financial data in our ERP application, we have…
The correct answer is D. Work with the executive management team to revise policies before allowing any remote. Before enabling remote access for a group handling sensitive financial data, security policies must be formally revised with executive management before any technical solution is deployed.
Question
A security manager has received the following email from the Chief Financial Officer (CFO):
"While I am concerned about the security of the proprietary financial data in our ERP application, we have had a lot of turnover in the accounting group and I am having a difficult time meeting our monthly performance targets. As things currently stand, we do not allow employees to work from home but this is something I am willing to allow so we can get back on track. What should we do first to securely enable this capability for my group?" Based on the information provided, which of the following would be the MOST appropriate response to the CFO?
Options
- ARemote access to the ERP tool introduces additional security vulnerabilities and should not
- BAllow VNC access to corporate desktops from personal computers for the users working
- CAllow terminal services access from personal computers after the CFO provides a list of the
- DWork with the executive management team to revise policies before allowing any remote
How the community answered
(29 responses)- A14% (4)
- B3% (1)
- C3% (1)
- D79% (23)
Why each option
Before enabling remote access for a group handling sensitive financial data, security policies must be formally revised with executive management before any technical solution is deployed.
Refusing remote access outright ignores the legitimate business need and fails to offer a risk-managed alternative, which is not a constructive or complete security response.
VNC from personal computers lacks strong authentication and channel encryption, introducing significant risk of credential theft and unauthorized access to corporate desktops.
Granting terminal services access based only on a CFO-provided user list bypasses formal risk assessment and policy approval, skipping the governance steps necessary for secure remote access.
Policy revision requires cross-functional executive alignment to define acceptable use, risk tolerance, and security requirements before technical controls are implemented. Without updated policies, any remote access solution lacks governance backing and could expose the organization to unmanaged risk, especially given the sensitivity of ERP financial data.
Concept tested: Security policy governance before enabling remote access
Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.