QuestionQ695

Risk Response and Reporting

Given a rise in regulatory penalties associated with data leakage incidents, which of the following approaches would be the MOST effective for building organization-wide awareness of data security?

A. Enforce sanctions for noncompliance with security procedures.

B. Require regular testing of the data breach response plan.

C. Conduct organization-wide phishing simulations.

D. Require training on the data handling policy.

  • A Enforce sanctions for noncompliance with security procedures.
  • B Require regular testing of the data breach response plan.
  • C Conduct organization-wide phishing simulations.
  • D Require training on the data handling policy.
Explanation

Training on the data handling policy directly educates employees across the organization on how data should be classified, stored, transmitted, and disposed of, which addresses the root cause of data leakage incidents. Awareness is best built through structured education that ensures staff understand their responsibilities and the rules governing data handling, rather than through punitive measures (sanctions), incident response testing (which validates the ability to respond after a breach rather than prevent one), or phishing simulations (which target a narrow attack vector rather than broad data handling practices). Requiring policy training ensures consistent, organization-wide understanding of expected behaviors, making it the most effective way to reduce the risk of data leakage and the associated regulatory penalties.

Community Discussion

No comments yet. Be the first to start the discussion!