GCFA · Question #33
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
The correct answer is C. Privacy policy. Monitoring employees' hard disks is governed by the organization's privacy policy, which defines the scope of employee data access and surveillance.
Question
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
Options
- ANetwork security policy
- BUser password policy
- CPrivacy policy
- DBackup policy
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C81% (17)
- D5% (1)
Why each option
Monitoring employees' hard disks is governed by the organization's privacy policy, which defines the scope of employee data access and surveillance.
A network security policy governs rules for protecting and accessing the network infrastructure, not the contents of individual employee hard disks.
A user password policy defines requirements for password creation, rotation, and complexity, not device monitoring practices.
A privacy policy outlines what personal or stored data an organization may access, monitor, and retain from employee devices. Periodically inspecting hard disks involves accessing potentially personal information, which falls under privacy policy jurisdiction. Organizations must disclose this type of monitoring in their privacy policy to maintain legal and ethical compliance.
A backup policy defines procedures and schedules for copying and restoring data, not the surveillance or inspection of employee storage devices.
Concept tested: Privacy policy scope covering employee device monitoring
Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.