Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 104
As the Head of IT Security for ThorTeaches.com, you are responsible for evaluating the potential risks of allowing employees to BYOD (Bring Your Own Device) to work. After conducting a thorough risk assessment, you have determined that the main risks associated with BYOD include data breaches, malware infections, and lost or stolen devices. However, ThorTeaches.com is facing pressure to implement a BYOD policy in order to stay competitive in the market. What is the best approach to managing the risks associated with BYOD?
- A Accept the risks and implement a BYOD policy without any additional security measures.
- B Mitigate the risks and implement a BYOD policy with additional security measures such as mobile device management and security training for employees.
- C Avoid the risks and prohibit the use of BYOD in the workplace.
- D Transfer the risks to a third party through the use of a mobile device management provider.
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Mitigate the risks and implement a BYOD policy with additional security measures such as mobile device management and security training for employees: A balanced approach would be to accept the risks associated with BYOD but mitigate them with proper security measures. One way to do this is by implementing a mobile device management (MDM) solution, which can provide centralized control and enforcement of corporate security policies across employees' devices. Additionally, security training for employees can enhance awareness about potential threats and instill good cybersecurity habits, reducing the chance of a breach due to human error. The incorrect answers: Accept the risks and implement a BYOD policy without any additional security measures: This approach exposes the organization to unnecessary risks, as it leaves potential vulnerabilities unaddressed. Data breaches, malware infections, and lost or stolen devices could result in significant operational and reputational damage, and potential legal and regulatory implications. Avoid the risks and prohibit the use of BYOD in the workplace: While this would theoretically eliminate the security risks associated with BYOD, it's not necessarily a feasible or practical approach in today's increasingly mobile and remote working environment. It may also reduce productivity and employee satisfaction, as it doesn't consider the convenience and flexibility BYOD offers. Transfer the risks to a third party through the use of a mobile device management provider: While using a third-party MDM provider can help manage the risks associated with BYOD, it does not entirely transfer the risk. The organization still maintains ultimate responsibility for its data security, and a breach could still have significant implications. It's also important to consider that this option does not address the need for employee security training. Normally risk transference is associated with buying insurance or sharing the risk through a partnership.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
