ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium
A company policy dictates that all 'Confidential' data must be stored on encrypted file shares and only accessible by authorized personnel with a 'need-to-know'. A junior administrator accidentally moves a folder containing 'Confidential' customer records to a publicly accessible unencrypted network share. Which of the following controls was PRIMARILY circumvented by this action?
- AData privacy regulations
- BData security controls
- CData retention policy
- DData ownership assignment
Show answer & explanationAnswer & explanation
Correct answer: B. Data security controls
The movement of 'Confidential' data to an unencrypted, publicly accessible share directly circumvents the implemented 'data security controls' (encrypted file shares, need-to-know access) designed to protect that specific classification of data.
Why the other options are wrong
- A. While this action likely violates privacy regulations, the direct failure was of the internal 'data security controls' that were meant to prevent such an exposure.
- C. Data retention policy relates to how long data is kept, not its immediate security measures during its lifecycle.
- D. Data ownership assigns responsibility, but the action itself violates the controls set by that owner.
Data Security Controls
Measures, both technical and administrative, implemented to protect the confidentiality, integrity, and availability of data throughout its lifecycle.
- Encompasses encryption, access controls, monitoring, and policies.
- Designed to enforce data classification and handling requirements.
- Aims to prevent unauthorized access, modification, or disclosure.
Memory trick: An accidental move skips the security guard.