ExamGecko
Question list
Search
Search

Related questions











Question 577 - CISA discussion

Report
Export

Which of the following management decisions presents the GREATEST risk associated with data leakage?

A.
There is no requirement for desktops to be encrypted
Answers
A.
There is no requirement for desktops to be encrypted
B.
Staff are allowed to work remotely
Answers
B.
Staff are allowed to work remotely
C.
Security awareness training is not provided to staff
Answers
C.
Security awareness training is not provided to staff
D.
Security policies have not been updated in the past year
Answers
D.
Security policies have not been updated in the past year
Suggested answer: C

Explanation:

The management decision that presents the greatest risk associated with data leakage is not providing security awareness training to staff. This is because staff are often the weakest link in the information security chain, and they may unintentionally or maliciously leak sensitive data through various channels, such as email, social media, cloud storage, or removable media. Security awareness training is essential to educate staff on the importance of protecting data, the policies and procedures for handling data, and the best practices for preventing and reporting data leakage incidents. Not requiring desktops to be encrypted, allowing staff to work remotely, and not updating security policies in the past year are also management decisions that may increase the risk of data leakage, but they are not as significant as not providing security awareness training to staff. Encryption, remote work, and security policies are technical or administrative controls that can be implemented or enforced by management, but they cannot fully prevent or mitigate human errors or malicious actions by staff.Reference:CISA Review Manual (Digital Version), [ISACA Privacy Principles and Program Management Guide]

asked 18/09/2024
Lal George
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first