Isaca Certified in the Governance of Enterprise IT Exam CGEIT Question # 193 Topic 20 Discussion
CGEIT Exam Topic 20 Question 193 Discussion:
Question #: 193
Topic #: 20
Which of the following should be the FIRST step for executive management to take in communicating what is considered acceptable use with regard to personally owned devices for company business?
A.
Require employees to read and sign a disclaimer.
B.
Develop and disseminate an applicable policy.
C.
Post awareness messages throughout the facility.
D.
Provide training on how to protect data on personal devices.
The first step for executive management to take in communicating what is considered acceptable use with regard to personally owned devices for company business is to develop and disseminate an applicable policy. A policy is a written set of rules and guidelines that defines the scope, objectives, roles, and responsibilities of the BYOD program. A policy also specifies the security, privacy, and usage requirements and expectations for the employees and the organization. A policy helps to establish a clear and consistent understanding of what is acceptable and unacceptable when using personal devices for work purposes, and what are the consequences of non-compliance. A policy also helps to mitigate the potential risks and challenges associated with BYOD, such as data breaches, device loss or theft, malware infections, legal liabilities, and support issues. A policy should be developed in consultation with relevant stakeholders, such asIT, HR, legal, and business units, and disseminated to all employees through various channels, such as email, intranet, training sessions, and awareness campaigns. References: BYOD Policies for Organizations (4 Examples) - Dashlane1, Mobile Device Security–Bring Your Own Device (BYOD): Draft SP 1800-22 …2, Personally Owned Device Policy — FBI
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit