
An offboarding sales representative downloaded customer profiles owned by the head of the sales department from the file server onto a USB dongle on the day he left and sold it online. This data breach occurred because of the miscommunication between the HR and IT departments. The HR department didn’t notify the IT department to disable the user accounts and revoke the privileges of the unhappy employee in time. As a CEO, which of the following roles do you think is accountable for the data breach of customer profiles? (Source: Wentz QOTD)
A. The system owner of the file server, due to inappropriate security controls
B. The vice president of HR, owing to lack of due care
C. The CIO, because of ineffective IT support for user provisioning/deprovisioning
D. The vice president of Sales, for the responsibility and authority of classification and protection
Continue reading →