CISA Certified Information Systems Auditor – Question2102

A data leakage prevention (DLP) solution has identified that several employees are sending confidential company data to their personal email addresses in violation of company policy. The information security manager should FIRST:

A.
initiate an investigation to determine the full extent of noncompliance
B. notify senior management that employees are breaching policy
C. limit access to the Internet for employees involved
D. contact the employees involved to retake security awareness training

Correct Answer: A