QuestionQ973

Technology and Security

A review of an organization’s controls has found that its data loss prevention (DLP) system is currently unable to detect outbound emails containing credit card data.

Which of the following would be MOST affected?

  • A Risk appetite
  • B Residual risk
  • C Key risk indicators (KRIs)
  • D Inherent risk
Explanation

Residual risk is the risk that remains after controls are applied. When a DLP control fails to detect outbound emails containing credit card data, the control is ineffective for that exposure and the remaining likelihood of unauthorized data disclosure increases.

Community Discussion

No comments yet. Be the first to start the discussion!