CISM · Question #983
A security review of an HR application reveals a file server containing confidential HR data is accessible to external user IDs. Which of the following should the information security manager do…
The correct answer is D. Remove access permissions for the external users. When confidential data is actively exposed, the first priority is containment - stop the bleeding immediately. Removing external access permissions eliminates the ongoing risk without delay. Confirming with the data owner (B) introduces unnecessary lag while the exposure…
Question
A security review of an HR application reveals a file server containing confidential HR data is accessible to external user IDs. Which of the following should the information security manager do FIRST?
Options
- AUpdate the existing data privacy policy.
- BConfirm the issue with the data owner.
- CTrain the HR team on proper access control.
- DRemove access permissions for the external users.
How the community answered
(32 responses)- A9% (3)
- B25% (8)
- C16% (5)
- D50% (16)
Explanation
When confidential data is actively exposed, the first priority is containment - stop the bleeding immediately. Removing external access permissions eliminates the ongoing risk without delay. Confirming with the data owner (B) introduces unnecessary lag while the exposure continues. Updating the data privacy policy (A) and training the HR team (C) are corrective and preventive actions that address root causes but do not stop the immediate harm. Security incident response follows: contain first, then investigate, then remediate systemic issues.
Topics
Community Discussion
No community discussion yet for this question.