QuestionQ139

Risk Response and Reporting

A risk practitioner has recently found that personal information from the production environment is needed for testing in non-production environments. Which of the following is the BEST recommendation to address this situation?

  • A Enable data encryption in the test environment.
  • B Enforce multi-factor authentication within the test environment.
  • C Prevent the use of production data in the test environment.
  • D De-identify data before being transferred to the test environment.
Explanation

Production-derived personal data used outside production should be de-identified before transfer so testing can proceed without exposing identifiable personal information. Encryption and multi-factor authentication are important safeguards, but they do not eliminate the privacy risk inherent in retaining identifiable data in a test environment.

Community Discussion

No comments yet. Be the first to start the discussion!