nerdexam
Isaca

CGEIT · Question #71

Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?

The correct answer is C. Educating employees on the increased IT security risk to the enterprise. The primary governance focus when implementing a new BYOD policy should be educating employees on the increased IT security risks introduced to the enterprise.

Submitted by emma.c· Apr 18, 2026Risk Optimization

Question

Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?

Options

  • ARecommending mobile applications that will increase business productivity
  • BTraining employees on the enterprise's chosen mobile device management system
  • CEducating employees on the increased IT security risk to the enterprise
  • DUnderstanding knowledge gaps of IT employees to support different mobile platforms

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    16% (4)
  • C
    72% (18)
  • D
    8% (2)

Why each option

The primary governance focus when implementing a new BYOD policy should be educating employees on the increased IT security risks introduced to the enterprise.

ARecommending mobile applications that will increase business productivity

Recommending productivity apps is a potential benefit, not the main governance focus, which is primarily risk and compliance management.

BTraining employees on the enterprise's chosen mobile device management system

Training on an MDM system is an operational implementation detail, secondary to the overarching governance focus on risk awareness and mitigation for the enterprise.

CEducating employees on the increased IT security risk to the enterpriseCorrect

BYOD policies introduce significant security risks because personal devices often lack the same level of security controls as corporate devices and can be endpoints for malware or data leakage. Educating employees on these risks and their responsibilities in mitigating them is crucial for maintaining enterprise security and compliance.

DUnderstanding knowledge gaps of IT employees to support different mobile platforms

Understanding IT staff knowledge gaps is an internal IT management concern, not the main governance focus for the policy itself regarding enterprise-wide security risk.

Concept tested: BYOD policy governance and security risk

Source: https://learn.microsoft.com/en-us/mem/intune/fundamentals/byod-introduction

Topics

#BYOD policy#IT security risk#Risk management#Employee awareness

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice