ExamGecko
Question list
Search
Search

Related questions

Question 140 - CISA discussion

Report
Export

Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?

A.
Require all employees to sign nondisclosure agreements (NDAs).
Answers
A.
Require all employees to sign nondisclosure agreements (NDAs).
B.
Develop an acceptable use policy for end-user computing (EUC).
Answers
B.
Develop an acceptable use policy for end-user computing (EUC).
C.
Develop an information classification scheme.
Answers
C.
Develop an information classification scheme.
D.
Provide notification to employees about possible email monitoring.
Answers
D.
Provide notification to employees about possible email monitoring.
Suggested answer: C

Explanation:

The most important task before implementing any associated email controls to prevent sensitive information from being emailed outside the organization by employees is to develop an information classification scheme. An information classification scheme is a framework that defines the categories and levels of sensitivity for different types of information, such as public, internal, confidential, or secret. An information classification scheme can help implement email controls by providing criteria and guidelines for identifying, labeling, handling, and protecting sensitive information in email attachments. The other options are not as important as developing an information classification scheme, as they do not address the root cause of the problem or provide the same benefits. Requiring all employees to sign nondisclosure agreements (NDAs) is a legal control that can help deter or penalize employees from disclosing sensitive information, but it does not prevent them from emailing it outside the organization. Developing an acceptable use policy for end-user computing (EUC) is a governance control that can help define and communicate the rules and expectations for using IT resources, such as email, but it does not prevent employees from emailing sensitive information outside the organization. Providing notification to employees about possible email monitoring is a transparency control that can help inform and warn employees about the potential consequences of emailing sensitive information outside the organization, but it does not prevent them from doing so.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.3.2

asked 18/09/2024
German Dario Jara
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first