CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, which could compromise sensitive customer credit card data. The risk practitioner recommends implementing endpoint detection and response (EDR) solutions on all POS terminals and configuring them to automatically quarantine suspicious processes. The primary control objective being addressed by this recommendation is:
- AAvailability
- BConfidentiality
- CNon-repudiation
- DIntegrity
Show answer & explanationAnswer & explanation
Correct answer: B. Confidentiality
The primary concern is the compromise of 'sensitive customer credit card data' due to malware. Implementing EDR to quarantine suspicious processes directly aims to prevent unauthorized disclosure of this data, which is the core objective of confidentiality.
Why the other options are wrong
- A. Availability ensures systems and data are accessible when needed, which is not the primary focus here.
- C. Non-repudiation ensures that an action or event cannot be denied by the parties involved, which is unrelated to preventing malware from compromising data.
- D. Integrity ensures data is accurate and complete, and not subject to unauthorized modification, which is a secondary concern to data compromise.
Control Objective: Confidentiality
Confidentiality is a control objective aimed at protecting sensitive information from unauthorized access, disclosure, or observation.
- Prevents data breaches and unauthorized viewing.
- Often achieved through encryption, access controls, and data masking.
- A core principle of information security (CIA triad).
Memory trick: CIA: Confidentiality, Integrity, Availability.