QuestionQ501

Technology and Security

An organization is implementing data warehousing infrastructure. Senior management is concerned with protecting client-data security in this new environment. What should the risk practitioner recommend be done NEXT?

  • A Ensure an attribute-based access control model is implemented.
  • B Ensure a role-based access control model is implemented.
  • C Perform a gap analysis regarding the organization’s client data access model.
  • D Establish new controls addressing a consistently applied data access model.
Explanation

A gap analysis of the organization’s client-data access model identifies the differences between current access controls and the access requirements for the new data warehouse. That assessment provides the risk-based basis for selecting and implementing an appropriate access-control model or additional controls. ISACA guidance describes identifying existing controls and performing a gap analysis before implementing new controls.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!