nerdexam
Isaca

CGEIT · Question #472

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the ass

The correct answer is B. Potential exposures and impacts using common terms. For a BYOD technical risk communication plan, it is most important to include potential exposures and impacts explained in common terms. This ensures all users understand the relevance and consequences of the risks, regardless of their technical background.

Submitted by salim_om· Apr 18, 2026Risk Optimization

Question

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options

  • AA link on the corporate intranet to the BYOD policy
  • BPotential exposures and impacts using common terms
  • CSchedule and content for mandatory training
  • DDisciplinary actions for violation of the BYOD policy

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    84% (27)
  • C
    9% (3)
  • D
    3% (1)

Why each option

For a BYOD technical risk communication plan, it is most important to include potential exposures and impacts explained in common terms. This ensures all users understand the relevance and consequences of the risks, regardless of their technical background.

AA link on the corporate intranet to the BYOD policy

Providing a link to the policy is important for reference but doesn't actively *communicate* the associated technical risks and their impacts in an accessible way.

BPotential exposures and impacts using common termsCorrect

When communicating technical risks to a broad audience, especially with a BYOD policy, it is crucial to explain potential exposures (e.g., data loss, malware infection) and their impacts (e.g., compromised personal data, company data breach) using common, non-technical terms. This ensures that all employees, regardless of their technical proficiency, understand *why* the risks are important and how they might personally be affected, fostering greater awareness and compliance.

CSchedule and content for mandatory training

A schedule for mandatory training is a component of a communication plan, but the *content* (i.e., the explanation of risks and impacts) is more fundamentally important than just the schedule.

DDisciplinary actions for violation of the BYOD policy

Disciplinary actions are important to include in the overall policy and training, but they are punitive; the *most important* aspect of risk communication is explaining the risks themselves and their consequences to drive informed behavior.

Concept tested: Effective risk communication

Topics

#Risk Communication#BYOD Policy#IT Risk Management#Communication Plan

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice