100-160 Question 140
Select 3Your organization has implemented a Bring Your Own Device (BYOD) policy, allowing employees to use personal devices for work purposes. During a recent audit, it was discovered that sensitive customer data is stored unencrypted on some employee devices. Which actions should you take to address this issue while ensuring compliance with relevant regulations like GDPR and HIPAA?
- A
Implement device encryption and enforce it through the Mobile Device Management (MDM) solution.
- B
Restrict the BYOD policy to trusted employees only instead of enforcing device-level security.
- C
Deploy a secure app for accessing and storing work data, ensuring it encrypts sensitive data.
- D
Regularly back up all data on personal devices to a shared company cloud storage system.
- E
Provide employee training on secure handling of sensitive data and regulatory compliance.
Show answer and explanation
Correct answers: A, C, E
Explanation
To address the issue of unencrypted sensitive data on personal devices in a BYOD environment, it is crucial to enforce security measures like device encryption and secure app usage while educating employees on regulatory compliance. These steps help ensure the organization meets requirements outlined in GDPR, HIPAA, and similar regulations while protecting sensitive data from unauthorized access.
- A. Correct.
Implementing device encryption is a critical first step to protect sensitive data stored on personal devices and is a requirement for compliance with regulations like GDPR and HIPAA.
- B. Incorrect.
Restricting BYOD to trusted employees does not address the underlying issue of securing sensitive data and fails to ensure compliance with regulations.
- C. Correct.
Using a secure app that encrypts sensitive data ensures that work-related data is protected even if the personal device is lost or compromised.
- D. Incorrect.
Backing up all data from personal devices to a shared cloud storage system could introduce additional risks and does not comply with data privacy regulations unless explicitly authorized.
- E. Correct.
Providing employee training is essential to ensure that users understand the importance of data security, encryption, and compliance with regulations like GDPR and HIPAA.