QuestionQ55

Protection of Information Assets

An IS auditor discovers that an organization's data loss prevention (DLP) system is configured with vendor-default settings to identify violations. The auditor's MAIN concern should be that:

Explanation

DLP detection and classification criteria must be tailored to the organization’s data sensitivity, regulatory requirements, and risk tolerance. Vendor-default settings may categorize violations in ways that do not align with the organization’s risk profile.

Community Discussion

No comments yet. Be the first to start the discussion!