Exam CISM All QuestionsBrowse all questions from this exam
Question 458

An organization permits the storage and use of its critical and sensitive information on employee-owned smartphones. Which of the following is the BEST security control?

    Correct Answer: D

    When an organization permits the storage and use of critical and sensitive information on employee-owned smartphones, the best security control is to establish the authority to remotely wipe data. This ensures that in the event a smartphone is lost, stolen, or an employee leaves the organization, the sensitive information can be securely erased to prevent unauthorized access or misuse. Monitoring usage, developing security awareness training, and requiring data backup, while valuable, do not directly address the risk of data loss or unauthorized access in scenarios where the device is no longer in the user's possession.

Discussion
beeverOption: B

It should be B - Developing security awareness training since it is on employee-owned smartphones, awareness would be the best security control of it

dark_3k03rOption: D

The correct solution would be (D) as the organization should be able to wipe the device in case it is stolen or misplaced. A. Could cause potential legal issues B. Developing security awareness training would do nothing to control the situation but only make users aware of the situation. C. Requiring the backup of the organization s data by the user does not address the fact that a device may be stolen or misplaced.

POWNEDOption: D

I don't believe awareness training is a control, will have to go with D on this one.

SoleandheelOption: D

D. Establishing the authority to remote wipe I'm going with D becuase, what if the threat is an insider threat. Maybe one of your employees decides to misuse company data deliberately. Training will not help in this situation. Remote Wipe is the best option in this scenario.

AaronS1990Option: D

This is D, if lost you need to delete the sensitive data B. Education does nothing. Everyone knows how to use and anyone could lose a phone.

richck102Option: D

D. Establishing the authority to remote wipe

SaisharanOption: D

Developing security awareness training (option B) is beneficial, but it alone may not provide sufficient control over the data stored on employee-owned smartphones. So the correct Option D

03allenOption: B

Does it make sense if you want to wipe other people's data on the same phone? Unless you install a separate enterprise OS. So user awareness is the best solution.

oluchecpointOption: D

Option D

GoseuOption: D

The best security control for what exactly ? I dont think training user is control , D is control but its very far fetched since you allow users to store and use data. It doesn’t feel like a realistic question .

RowlandmarcOption: B

I believe B is the better of the two... educating the user on appropriate use cases and how to manage the data etc... comparing this to option D which is the single control to wipe it once reported the phone is missing etc... user education provides that much more value

[Removed]

educating does nothing if they lose the phone. you need to wipe then