CAS-002 · Question #661
A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in…
The correct answer is A. Provide targeted security awareness training and impose termination for repeat violators. The manager's violation stemmed from a lack of security awareness rather than malicious intent, making targeted training the most proportionate and effective corrective control.
Question
A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in training was to log into the payroll system, and then activate desktop sharing with a trusted subordinate. The manager granted the subordinate control of the desktop thereby giving the subordinate full access to the payroll system. The subordinate did not have authorization to be in the payroll system. Another employee reported the incident to the security team. Which of the following would be the MOST appropriate method for dealing with this issue going forward?
Options
- AProvide targeted security awareness training and impose termination for repeat violators.
- BBlock desktop sharing and web conferencing applications and enable use only with approval.
- CActively monitor the data traffic for each employee using desktop sharing or web
- DPermanently block desktop sharing and web conferencing applications and do not allow its
How the community answered
(28 responses)- A82% (23)
- B4% (1)
- C11% (3)
- D4% (1)
Why each option
The manager's violation stemmed from a lack of security awareness rather than malicious intent, making targeted training the most proportionate and effective corrective control.
Targeted security awareness training directly addresses the root cause - the manager failed to recognize that sharing desktop control of a privileged system with an unauthorized user violates access control policy. Pairing training with a progressive discipline policy including termination for repeat offenses creates both an educational effect and a deterrent, while preserving legitimate desktop sharing capabilities for the organization.
Requiring approval for all desktop sharing is a disproportionately broad technical restriction that penalizes all users for one policy violation and does not address the underlying security awareness gap.
Actively monitoring all desktop sharing traffic for every employee is a disproportionate surveillance measure that does not resolve the root cause and introduces significant privacy concerns.
Permanently blocking all desktop sharing removes a legitimate and valuable business productivity tool from the entire organization based on a single policy violation, which is an overly punitive and operationally harmful response.
Concept tested: Security awareness training as corrective response to access policy violations
Source: https://csrc.nist.gov/publications/detail/sp/800-50/final
Topics
Community Discussion
No community discussion yet for this question.