ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy

A global pharmaceutical company is conducting an internal audit of its research and development data. The audit reveals that highly sensitive experimental drug formulas are being stored on unencrypted, publicly accessible cloud storage buckets. Which of the following data security controls has most critically failed in this scenario?

  1. AAccess control lists (ACLs)
  2. BData masking
  3. CData loss prevention (DLP)
  4. DData encryption at rest
Show answer & explanation

Correct answer: D. Data encryption at rest

Storing highly sensitive experimental drug formulas on unencrypted, publicly accessible cloud storage buckets is a direct failure of data encryption at rest. While other controls might also be weak, the absence of encryption for sensitive data in an accessible location is the most critical failure.

Why the other options are wrong

  • A. ACLs control who can access data, but if the data is publicly accessible, ACLs are not properly implemented or enforced.
  • B. Data masking changes data to hide sensitive information but doesn't protect the original data if exposed.
  • C. DLP aims to prevent data from leaving authorized perimeters, but the data is already exposed in publicly accessible storage.

Data Encryption at Rest

The process of encrypting data while it is stored on any device, such as hard drives, databases, or cloud storage, to protect it from unauthorized access.

  • Protects data even if the storage medium is stolen or compromised.
  • Essential for sensitive data stored in public or untrusted environments.
  • Can be implemented at the file, volume, or database level.

Memory trick: Always Encrypt Sensitive Data, Rest Assured.

More Asset Security questions