CRISC Certified in Risk and Information Systems ControlGovernanceHard

An organization's internal audit department identifies a pattern of non-compliance with a critical data retention policy, particularly among remote employees who use personal devices. The board of directors is concerned about potential regulatory fines and data leakage. Which of the following actions demonstrates the BEST integration of governance and risk management to address this issue?

  1. AConducting an exhaustive legal review of all past data retention practices to assess potential fines.
  2. BImplementing a technical solution to automatically enforce data retention on all devices, coupled with updated policy communication and training.
  3. CIssuing a stricter memo to all employees reiterating the data retention policy and threatening disciplinary action.
  4. DDelegating the entire issue to the IT department to find a technical fix without further management involvement.
Show answer & explanation

Correct answer: B. Implementing a technical solution to automatically enforce data retention on all devices, coupled with updated policy communication and training.

The best integration involves a multi-faceted approach: a technical control to enforce the policy, combined with updated communication and training to ensure employees understand and accept the changes. This addresses both the technical gap and the human element, which is key for effective governance and risk management.

Why the other options are wrong

  • A. An exhaustive legal review of past practices is reactive and doesn't proactively address the ongoing non-compliance or prevent future incidents, although it may be a secondary step.
  • C. While communication is important, simply issuing a memo doesn't address the root cause of non-compliance, especially with personal devices, and may not be effective without enforcement.
  • D. Delegating without management involvement lacks governance oversight and may lead to a technical solution that doesn't fully address the policy or employee usage issues.

Integrated Policy Enforcement

A governance and risk management strategy that combines technical controls for automated policy enforcement with clear communication, training, and ongoing monitoring to ensure consistent adherence to organizational policies, especially in complex environments like remote work and personal device usage.

  • Combines technical and human elements.
  • Crucial for compliance and risk mitigation.
  • Addresses root causes of non-compliance effectively.

Memory trick: Solve policy gaps with tech and teach, for full compliance reach.

More Governance questions