medium
Single Answer
0Alekos is responsible for the security of payment card information stored in a database. Policy directs that he remove the information from the database, but he cannot do this for operational reasons. He obtained an exception to policy and is seeking an appropriate compensating control to mitigate the risk. What would be his best option?
Answer Options
A
Purchasing insurance
B
Encrypting the database contents
C
Removing the data
D
Objecting to the exception
Correct Answer: B
Explanation
Alekos should encrypt the data to provide an additional layer of protection as a compensating control. The organization has already made a policy exception, so he should not react by objecting to the exception or removing the data without authorization. Purchasing insurance may transfer some of the risk but is not a mitigating control.