CGEIT · Question #72
An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A…
The correct answer is A. Authorize a risk analysis of the practice. The first strategic action to address the unauthorized use of an offsite cloud for sensitive data analysis, even if not explicitly prohibited, is to authorize a formal risk analysis of the practice.
Question
An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?
Options
- AAuthorize a risk analysis of the practice.
- BUpdate data governance practices.
- CRevise the information security policy.
- DRecommend the use of a private cloud.
How the community answered
(26 responses)- A65% (17)
- B4% (1)
- C23% (6)
- D8% (2)
Why each option
The first strategic action to address the unauthorized use of an offsite cloud for sensitive data analysis, even if not explicitly prohibited, is to authorize a formal risk analysis of the practice.
Although the practice is not prohibited by current policies, using an offsite cloud for sensitive data without prior authorization or assessment introduces significant, unknown risks. A formal risk analysis is the necessary first step to understand the potential impact, likelihood, and existing controls (or lack thereof) before any other corrective or policy-related actions can be effectively planned.
Updating data governance practices would follow a risk analysis, as you need to understand the risks before defining appropriate governance.
Revising the information security policy is a reactive measure that should be based on the findings of a comprehensive risk analysis.
Recommending a private cloud is a potential solution, but it's premature without first understanding the risks of the current situation and the requirements for a secure alternative.
Concept tested: Prioritizing risk assessment in new IT practices
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.