IS 監査人が組織のデータ損失防止 (DLP) 制御の運用有効性を評価する最も信頼できる方法は次のうちどれですか?
正解:D
Explanation The most reliable way for an IS auditor to evaluate the operational effectiveness of an organization's data loss prevention (DLP) controls is to verify that confidential files cannot be transmitted to a personal USB device. This is because DLP controls are designed to prevent the loss, leakage or misuse of sensitive data through breaches, ex-filtration transmissions and unauthorized use1. A personal USB device is a common way for data to be stolen or compromised, as it can bypass network security measures and allow unauthorized access to confidential files. Therefore, testing the DLP controls by attempting to copy or transfer confidential files to a personal USB device can provide a direct and objective evidence of whether the DLP controls are working as intended or not. The other options are less reliable ways for an IS auditor to evaluate the operational effectiveness of an organization's DLP controls. Reviewing data classification levels based on industry best practice is a way to assess the adequacy of the organization's data protection policies, but it does not measure how well the DLP controls are implemented or enforced in practice. Verifying that current DLP software is installed on all computer systems is a way to check the technical configuration of the DLP solution, but it does not test how well the DLP software detects and prevents data loss incidents in real scenarios. Conducting interviews to identify possible data protection vulnerabilities is a way to gather qualitative information from stakeholders, but it does not provide quantitative or empirical data on the actual performance of the DLP controls. References: What is Data Loss Prevention (DLP)? [Guide] - CrowdStrike