nerdexam
Isaca

CGEIT · Question #29

Which of the following would be MOST important to update if a decision is made to ban end user- owned devices in the workplace?

The correct answer is C. Enterprise acceptable use policy. If end user-owned devices are banned in the workplace, the most important document to update is the Enterprise Acceptable Use Policy to formally establish and enforce this new rule.

Submitted by chiamaka_o· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following would be MOST important to update if a decision is made to ban end user- owned devices in the workplace?

Options

  • AEmployee nondisclosure agreement
  • BEnterprise risk appetite statement
  • CEnterprise acceptable use policy
  • DOrientation training materials

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    85% (28)
  • D
    3% (1)

Why each option

If end user-owned devices are banned in the workplace, the most important document to update is the Enterprise Acceptable Use Policy to formally establish and enforce this new rule.

AEmployee nondisclosure agreement

An employee nondisclosure agreement relates to protecting confidential information, not directly to the policy on device ownership in the workplace.

BEnterprise risk appetite statement

The enterprise risk appetite statement defines the level of risk the organization is willing to accept; while the ban might be driven by risk, the AUP is the operational document for enforcement.

CEnterprise acceptable use policyCorrect

The Enterprise Acceptable Use Policy (AUP) is the most important document to update because it directly governs user conduct and defines what is permissible or prohibited regarding organizational IT resources, including device usage in the workplace.

DOrientation training materials

Orientation training materials would certainly need updating, but the policy itself (AUP) is the foundational document that dictates the content of such training.

Concept tested: Acceptable Use Policy (AUP)

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/acceptable-use-policy-template?view=o365-worldwide

Topics

#Acceptable Use Policy#BYOD Policy#IT Policy Management#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice