ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is evaluating an organization's data loss prevention (DLP) solution. The DLP solution is currently configured only to monitor outbound email for sensitive data. The CISA identifies that employees frequently use cloud-based file-sharing services and instant messaging applications for internal and external communication, which are not covered by the DLP. What is the MOST critical recommendation the CISA should make to enhance the effectiveness of the DLP solution?

  1. AConduct more frequent security awareness training on data handling.
  2. BExpand DLP coverage to include cloud file-sharing and instant messaging.
  3. CUpgrade the DLP solution to a newer version.
  4. DImplement stricter email usage policies for employees.
Show answer & explanation

Correct answer: B. Expand DLP coverage to include cloud file-sharing and instant messaging.

The current DLP solution has a significant blind spot by only monitoring email. Since employees are using other channels (cloud file-sharing, instant messaging) for sensitive data, expanding DLP coverage to these channels directly addresses the identified gap and is the most critical step to prevent data loss.

Why the other options are wrong

  • A. Training is a good complementary control, but it doesn't replace the need for technical controls in uncovered areas.
  • C. Upgrading might offer new features, but the immediate and most critical need is to extend existing capabilities to uncovered channels, which might be possible with the current version.
  • D. Policies are important, but without technical enforcement via DLP on other channels, they are less effective.

DLP Coverage Expansion

The process of extending Data Loss Prevention (DLP) controls to cover all relevant data egress points and communication channels within an organization, beyond just traditional email.

  • Ensures comprehensive protection of sensitive data.
  • Addresses modern communication methods (cloud, messaging).
  • Reduces the risk of data exfiltration through unmonitored channels.

Memory trick: Don't just guard the front door; check the windows and back gates too.

More Domain 5: Protection of Information Assets questions