nerdexam
Isaca

CGEIT · Question #558

An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be d

The correct answer is C. Require staff training on data classification policies.. To address staff saving sensitive corporate data to public cloud storage, the FIRST step should be to educate employees on existing data classification policies to ensure they understand what data is sensitive and where it can be stored.

Submitted by weili_xi· Apr 18, 2026Governance of Enterprise IT

Question

An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?

Options

  • ACreate a secure corporate cloud file storage and sharing solution.
  • BBlock corporate access to cloud file storage applications.
  • CRequire staff training on data classification policies.
  • DRevise the data management policy to prohibit this practice.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    11% (2)
  • C
    63% (12)
  • D
    21% (4)

Why each option

To address staff saving sensitive corporate data to public cloud storage, the FIRST step should be to educate employees on existing data classification policies to ensure they understand what data is sensitive and where it can be stored.

ACreate a secure corporate cloud file storage and sharing solution.

Creating a secure corporate solution is a good long-term strategy, but it doesn't immediately address the existing unauthorized use and lack of employee awareness.

BBlock corporate access to cloud file storage applications.

Blocking access is a reactive technical control that can disrupt legitimate business processes and should typically follow attempts to educate and enforce policies.

CRequire staff training on data classification policies.Correct

Often, employees are unaware of the sensitivity of certain data or the approved storage locations, making training on data classification and corresponding policies essential. This foundational step empowers staff to make informed decisions about data handling, mitigating the risk at the source by increasing awareness and compliance with established rules.

DRevise the data management policy to prohibit this practice.

Revising the data management policy might be necessary, but without ensuring staff understanding and training on even existing policies, a revised policy alone will not solve the behavioral issue.

Concept tested: Data governance and employee awareness for data security

Topics

#Data classification#Security awareness training#Information governance#Policy enforcement

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice