QuestionQ116

Information Security Management

An organization that processes credit card data has a policy stating that all card data must be encrypted whenever it is stored on a computer system. The policy is intended to reduce the chance that this confidential data becomes available to third parties, either through an attack or through carelessness.

What is the BEST way to ensure that the organization complies with the policy?

  • A Train all staff to ensure that they understand how encryption works, and why it is important to the organization
  • B Include a copy of the organization's security policy in every staff member's job description
  • C Prohibit the storage of credit card numbers on computer systems
  • D Use tools to detect and report any credit card numbers that have been stored unencrypted
Explanation

Tools that detect and report credit card numbers stored without encryption directly monitor the policy requirement, identify violations, and support prompt remediation. Awareness training and policy distribution do not establish or verify compliance.

Community Discussion

No comments yet. Be the first to start the discussion!