ExamGecko
Question list
Search
Search

Related questions











Question 463 - CISA discussion

Report
Export

Which of the following areas is MOST likely to be overlooked when implementing a new data classification process?

A.
End-user computing (EUC) systems
Answers
A.
End-user computing (EUC) systems
B.
Email attachments
Answers
B.
Email attachments
C.
Data sent to vendors
Answers
C.
Data sent to vendors
D.
New system applications
Answers
D.
New system applications
Suggested answer: A

Explanation:

The area that is most likely to be overlooked when implementing a new data classification process is end-user computing (EUC) systems. EUC systems are applications or tools that are developed or customized by end users, often without formal IT involvement or approval. EUC systems may contain sensitive or confidential data that need to be classified and protected according to the organization's policies and standards. However, EUC systems may not be subject to the same controls, oversight, or documentation as formal IT systems, and may not be included in the scope of the data classification process. Therefore, EUC systems pose a significant risk of data leakage, unauthorized access, or noncompliance. The other areas (B, C and D) are less likely to be overlooked, as they are more visible and manageable by the IT department or the data owners.Reference:IS Audit and Assurance Guideline 2202: Evidence Collection Techniques,CISA Review Manual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.2: Data Classification

asked 18/09/2024
Joan Campo
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first