nerdexam
Isaca

CGEIT · Question #44

A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should…

The correct answer is D. Assess the BYOD risk. After a business case indicates cost reduction by implementing a BYOD program, the first governance action should be to assess the associated BYOD risks.

Submitted by salim_om· Apr 18, 2026Risk Optimization

Question

A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should be the FIRST governance action?

Options

  • AAssess the enterprise architecture (EA).
  • BUpdate the network infrastructure.
  • CUpdate the BYOD policy.
  • DAssess the BYOD risk.

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    15% (5)
  • D
    73% (24)

Why each option

After a business case indicates cost reduction by implementing a BYOD program, the first governance action should be to assess the associated BYOD risks.

AAssess the enterprise architecture (EA).

Assessing enterprise architecture might be part of the technical planning, but risk assessment precedes it as a governance priority.

BUpdate the network infrastructure.

Updating the network infrastructure is an implementation step, which should follow a thorough risk assessment and policy definition.

CUpdate the BYOD policy.

Updating the BYOD policy is a crucial step, but it must be informed by a prior assessment of the specific risks the policy needs to address and mitigate.

DAssess the BYOD risk.Correct

Before adopting a BYOD program, particularly one involving access to corporate email on personal devices, assessing the BYOD risk is the essential first governance action. This assessment identifies potential security vulnerabilities, data privacy concerns, compliance issues, and operational impacts that must be understood and mitigated before proceeding with policy updates or infrastructure changes.

Concept tested: Risk assessment for new technology adoption

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-risk-assessment

Topics

#BYOD#Risk Assessment#IT Governance#Program Initiation

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice