QuestionQ210

The U.S. Privacy Environment

What could the company have done differently before the breach to lower its risk?

  • A Implemented a comprehensive policy for accessing customer information.
  • B Honored the promise of its privacy policy to acquire information by using an opt-in method.
  • C Looked for any persistent threats to security that could compromise the company’s network.
  • D Communicated requests for changes to users’ preferences across the organization and with third parties.
Explanation

A comprehensive policy governing access to customer information would enforce need-to-know access and least privilege, limiting employees to the data necessary for their assigned work. This reduces unnecessary exposure of sensitive customer and financial records. NIST defines least privilege as restricting access privileges to the minimum required to accomplish assigned tasks.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!