CCSP · Question #239
You are the security manager for an online retail sales company with 100 employees and a production environment hosted in a PaaS model with a major cloud provider. Your company policies have allowed…
The correct answer is A. Regular and widespread integrity checks on sampled data throughout the managed environment. Given the risks associated with BYOD and user-selected APIs accessing company data, regular and widespread integrity checks on sampled data are a critical security control.
Question
You are the security manager for an online retail sales company with 100 employees and a production environment hosted in a PaaS model with a major cloud provider. Your company policies have allowed for a BYOD workforce that work equally from the company offices and their own homes or other locations. The policies also allow users to select which APIs they install and use on their own devices in order to access and manipulate company data. Of the following, what is a security control you'd like to implement to offset the risk(s) incurred by this practice?
Options
- ARegular and widespread integrity checks on sampled data throughout the managed environment
- BMore extensive and granular background checks on all employees, particularly new hires
- CInclusion of references to all applicable regulations in the policy documents
- DIncreased enforcement of separation of duties for all workflows
How the community answered
(39 responses)- A79% (31)
- B10% (4)
- C3% (1)
- D8% (3)
Why each option
Given the risks associated with BYOD and user-selected APIs accessing company data, regular and widespread integrity checks on sampled data are a critical security control.
With a BYOD policy and users installing their own APIs to access company data, there's a significant risk of data corruption, unauthorized modification, or introduction of vulnerabilities. Regular and widespread integrity checks on sampled data help detect any unauthorized changes or inconsistencies in the data, thereby mitigating the risks associated with potentially compromised devices or insecure API usage.
More extensive background checks primarily address the risk from new hires or employee trustworthiness, not directly the technical risks posed by BYOD devices and user-selected APIs accessing data.
Including references to regulations in policy documents is a good governance practice but does not provide a direct technical control to mitigate the immediate data risks from BYOD and API usage.
Increased enforcement of separation of duties helps prevent a single individual from performing critical actions, but it doesn't directly address the technical integrity and security risks introduced by user-managed devices and third-party APIs manipulating company data.
Concept tested: BYOD security risks, data integrity controls
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.