IS 監査人は、ある従業員が機密データに不正アクセスしていることを発見しました。IS 監査人の最善の推奨事項は次のようになります。
正解:B
The best recommendation for an IS auditor who finds that one employee has unauthorized access to confidential data is to require the business owner to conduct regular access reviews. Access reviews are periodic assessments of user access rights and permissions to ensure that they are appropriate, necessary, and aligned with the business needs and objectives. Access reviews help to identify and remediate any unauthorized, excessive, or obsolete access that could pose a security risk or violate compliance requirements. The business owner is responsible for defining and approving the access requirements for their data and ensuring that they are enforced and monitored. References: * CISA Review Manual (Digital Version) * CISA Questions, Answers & Explanations Database