CISA Certified Information Systems Auditor – Question2127

On a daily basis, an in-house development team moves duplicate copies of production data containing personally identifiable information (PII) to the test environment. Which of the following is the BEST way to mitigate the privacy risk involved?

A.
Require data owners to sign off on production data.
B. Encrypt the data file.
C. Obtain customer opt-in acceptances.
D. Sanitize the data in the test environment.

Correct Answer: B