ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium
A software development company uses an agile methodology and frequently deploys updates to its customer-facing applications. The company processes customer payment information. To comply with PCI DSS and ensure that sensitive cardholder data is never stored on developer workstations or in non-production environments, which of the following is the MOST effective administrative control?
- AEstablishing a formal data handling policy with clear prohibitions.
- BImplementing strong encryption for all developer laptops.
- CEnforcing mandatory data sanitization for all test data.
- DDeploying a data loss prevention (DLP) system across the network.
Show answer & explanationAnswer & explanation
Correct answer: A. Establishing a formal data handling policy with clear prohibitions.
While technical controls like encryption and DLP are important, the MOST effective *administrative control* is a formal data handling policy. This policy clearly defines rules, prohibitions, and responsibilities, setting the foundational expectation for secure data handling. Technical controls support and enforce the policy, but the policy itself provides the directive and accountability.
Why the other options are wrong
- B. Encryption is a technical control, not an administrative one, and primarily protects data at rest if the device is lost, not from being copied to unauthorized locations.
- C. Data sanitization is a technical process, not an administrative control, and applies to data that has already been used, not preventing its initial unauthorized presence.
- D. DLP is a technical control that attempts to enforce policy, but the policy itself must first be established as the administrative directive.
Administrative Controls (Data Handling)
Policies, procedures, and guidelines established by management to govern the behavior of personnel and the management of information assets, ensuring adherence to security objectives.
- Define 'how' data should be handled and protected.
- Provide the framework for technical and physical controls.
- Examples include security policies, standards, and awareness training.
Memory trick: Admin tells, Tech does, Phys secures.