CISA · Question #174
Which of the following is the BEST approach to help organizations address risks associated with shadow IT?
The correct answer is D. Conducting regular security assessments to identify unauthorized systems and solutions. Shadow IT refers to systems, software, or services used by employees without explicit IT approval. You cannot manage what you cannot see, so conducting regular security assessments to identify unauthorized systems (D) is the most effective approach - it surfaces what shadow IT ac
Question
Which of the following is the BEST approach to help organizations address risks associated with shadow IT?
Options
- AImplementing policies that prohibit the use of unauthorized systems and solutions
- BTraining employees on information security and conducting routine follow-ups
- CProviding employees with access to necessary systems and unlimited software licenses
- DConducting regular security assessments to identify unauthorized systems and solutions
How the community answered
(61 responses)- A7% (4)
- B11% (7)
- C3% (2)
- D79% (48)
Explanation
Shadow IT refers to systems, software, or services used by employees without explicit IT approval. You cannot manage what you cannot see, so conducting regular security assessments to identify unauthorized systems (D) is the most effective approach - it surfaces what shadow IT actually exists so the organization can evaluate, remediate, or formally adopt those solutions. Policies prohibiting unauthorized systems (A) are necessary but unenforceable without detection mechanisms. Training (B) raises awareness but does not discover existing shadow IT. Providing unlimited software licenses (C) is impractical, costly, and does not address the underlying governance or security risks.
Topics
Community Discussion
No community discussion yet for this question.