企業の環境における組織のモバイル デバイス ポリシーと制御を確認する IS 監査人にとって、次のどれが最も重要であるでしょうか。
正解:C
Comprehensive and Detailed Step-by-Step Explanation: A lack ofMobile Device Management (MDM) enrollmentis the biggest concern, asunmanaged devicespose a serious security risk. * Not All Devices Enrolled in MDM (Correct Answer - C) * Unenrolled devices can bypass security policies. * Example:A stolen, unenrolled device may lack encryption, exposing corporate data. * Biometric Authentication Required (Incorrect - A) * Biometrics are anenhanced security measure, not a concern. * VPN Not Required for Internal Network (Incorrect - B) * VPNs are typically used for external access, not always needed internally. * Remote Wipe Requires Internet (Incorrect - D) * A limitation but stillless riskythan allowing unsecured devices. References: * ISACA CISA Review Manual * NIST 800-124 (Mobile Device Security)