What should be an IS auditor's GREATEST concern when an organization's virtual private network (VPN) is implemented on employees' personal mobile devices?
A.
Users may access services over the VPN that are network resource intensive.
B.
Users may store the data in plain text on their mobile devices.
C.
Users may access the corporate network from unauthorized devices.
D.
Users may access services not supported by the VPN.
When employees use personal mobile devices to access a VPN, the greatest concern for an IS auditor is the potential for sensitive data to be stored in an unsecured manner. If data is stored in plain text, it could be easily accessed by unauthorized parties if the device is lost, stolen, or compromised. This risk is heightened when the devices are not managed by the organization’s IT department, which would typically enforce security policies such as encryption.
References: ISACA’s resources on securing mobile devices and VPN technology assurance emphasize the importance of implementing strong security controls to protect sensitive data on mobile devices. This includes ensuring that data is not stored in plain text and is instead encrypted to prevent unauthorized access1234. The use of mobile device management (MDM) software is also advocated to remotely manage and secure mobile devices used for corporate access1.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit