CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 640


A review of Internet security disclosed that users have individual user accounts with Internet service providers (ISPs) and use these accounts for downloading business data. The organization wants to ensure that only the corporate network is used. The organization should FIRST:

Show Answer
Correct Answer: C

To ensure that only the corporate network is used for downloading business data, the organization should first include a statement in its security policy about Internet use. Establishing clear policies and guidelines provides a foundation for acceptable and secure Internet usage, setting expectations for employees. Once these policies are in place, the organization can implement technical controls or monitoring measures to enforce them.

Discussion

5 comments
Sign in to comment
3008Option: A
Jun 4, 2023

the organization should FIRST use a proxy server to filter out Internet sites that should not be accessed, as this provides an effective means of controlling access to the Internet and preventing users from accessing non-business-related websites or services that could compromise the security of the corporate network.

starzuu
Jul 29, 2023

yeah to have the proxy server set like that you need a policy first. It's C.

3008
Sep 2, 2023

C, including a statement in the security policy about Internet use, is important but is not a complete solution in itself. A policy statement alone does not provide a mechanism for enforcing the policy, and it may not be sufficient to prevent users from accessing non-business-related websites or services.

JONESKAOption: C
Jul 16, 2023

I think its C. Before implementing any technical controls or monitoring measures, it is essential for the organization to establish clear policies and guidelines regarding Internet use. By including a statement in its security policy about Internet use, the organization sets expectations and provides employees with guidelines on acceptable and secure Internet usage.

Yejide03Option: C
Feb 21, 2024

C. include a statement in its security policy about Internet use

topikalOption: D
Jun 24, 2024

I vote for D

SwallowsOption: A
Jul 6, 2024

It is important to first implement a proxy server to control access to certain internet sites, and then update your security policies to clarify the rules and regulations for internet usage.