CGEIT · Question #558
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be d
The correct answer is C. Require staff training on data classification policies.. To address staff saving sensitive corporate data to public cloud storage, the FIRST step should be to educate employees on existing data classification policies to ensure they understand what data is sensitive and where it can be stored.
Question
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
Options
- ACreate a secure corporate cloud file storage and sharing solution.
- BBlock corporate access to cloud file storage applications.
- CRequire staff training on data classification policies.
- DRevise the data management policy to prohibit this practice.
How the community answered
(19 responses)- A5% (1)
- B11% (2)
- C63% (12)
- D21% (4)
Why each option
To address staff saving sensitive corporate data to public cloud storage, the FIRST step should be to educate employees on existing data classification policies to ensure they understand what data is sensitive and where it can be stored.
Creating a secure corporate solution is a good long-term strategy, but it doesn't immediately address the existing unauthorized use and lack of employee awareness.
Blocking access is a reactive technical control that can disrupt legitimate business processes and should typically follow attempts to educate and enforce policies.
Often, employees are unaware of the sensitivity of certain data or the approved storage locations, making training on data classification and corresponding policies essential. This foundational step empowers staff to make informed decisions about data handling, mitigating the risk at the source by increasing awareness and compliance with established rules.
Revising the data management policy might be necessary, but without ensuring staff understanding and training on even existing policies, a revised policy alone will not solve the behavioral issue.
Concept tested: Data governance and employee awareness for data security
Topics
Community Discussion
No community discussion yet for this question.