CGEIT · Question #200
An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits,
The correct answer is B. Improve training courses on securing corporate information.. To address the security risks of employees using personal devices for corporate business while maintaining business benefits, the committee should prioritize mitigating human-related security risks.
Question
An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, what should be the committee's FIRST recommendation?
Options
- ADocument procedures for securing personal devices.
- BImprove training courses on securing corporate information.
- CPerform a risk assessment on personal device data protection.
- DUpdate the corporate security policy to include personal devices.
How the community answered
(58 responses)- A3% (2)
- B76% (44)
- C12% (7)
- D9% (5)
Why each option
To address the security risks of employees using personal devices for corporate business while maintaining business benefits, the committee should prioritize mitigating human-related security risks.
Documenting procedures is important, but without prior training, employees may not understand or follow them effectively, making it a secondary step to immediate risk mitigation.
Improving training courses on securing corporate information directly addresses the immediate human factor of risk by educating employees on safe practices when using personal devices for business. This proactive measure ensures that employees understand how to protect sensitive corporate data immediately, given they are already using these devices.
Performing a risk assessment is a foundational step for understanding risks, but it doesn't immediately mitigate the ongoing security risk from current user behavior.
Updating the corporate security policy is essential for formalizing rules, but without training, it may not immediately change employee behavior or secure existing usage effectively.
Concept tested: Mitigating insider security risks
Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-data-protection-training
Topics
Community Discussion
No community discussion yet for this question.