Isaca Certified in Risk and Information Systems Control CRISC Question # 437 Topic 44 Discussion
CRISC Exam Topic 44 Question 437 Discussion:
Question #: 437
Topic #: 44
A public online information security training course is available to an organization's staff. The online course contains free-form discussion fields. Which of the following should be of MOST concern to the organization's risk practitioner?
A.
The form may be susceptible to SQL injection attacks.
B.
Data is not encrypted in transit to the site.
C.
Proprietary corporate information may be disclosed.
D.
Staff nondisclosure agreements (NDAs) are not in place.
Free-form fields in public forums increase the risk of accidental or intentional disclosure of sensitive or proprietary information. This creates legal and reputational exposure. Monitoring or disabling such features is essential to mitigating data leakage risks.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit