nerdexam
Isaca

CISM · Question #480

Senior management is concerned about data exposure through the use of public AI services. Which of the following is the information security manager's BEST course of action?

The correct answer is A. Perform a risk assessment of public AI with appropriate recommendations for senior. The best course of action is to conduct a risk assessment to evaluate the potential risks and threats associated with public AI services. This allows the organization to make informed decisions and implement appropriate security controls, policies, or restrictions based on…

Submitted by tom_us· Apr 18, 2026Information Security Risk Management

Question

Senior management is concerned about data exposure through the use of public AI services. Which of the following is the information security manager's BEST course of action?

Options

  • APerform a risk assessment of public AI with appropriate recommendations for senior
  • BDisable access to public AI from company devices.
  • CPerform a business impact analysis (BIA) of public AI.
  • DTrain all employees on the appropriate use of public AI services and confidential data.

How the community answered

(19 responses)
  • A
    79% (15)
  • B
    11% (2)
  • C
    5% (1)
  • D
    5% (1)

Explanation

The best course of action is to conduct a risk assessment to evaluate the potential risks and threats associated with public AI services. This allows the organization to make informed decisions and implement appropriate security controls, policies, or restrictions based on business needs. While disabling access, conducting a BIA, and training employees are useful, they should be based on the findings of a comprehensive risk assessment rather than a reactive approach.

Topics

#Risk Assessment#AI Security#Data Exposure#Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice