During the security review of organizational servers it was found that a file server containing
confidential human resources (HR) data was accessible to all user IDs. As a FIRST step, the
security manager should:
A.
copy sample files as evidence.
B.
remove access privileges to the folder containing the data.
C.
report this situation to the data owner.
D.
train the HR team on properly controlling file permissions.
Explanation:
The data owner should be notified prior to any action being taken. Copying sample files as
evidence is not advisable since it breaches confidentiality requirements on the file. Removing
access privileges to the folder containing the data should be done by the data owner or by the
security manager in consultation with the data owner, however, this would be done only after
formally reporting the incident. Training the human resources (MR) team on properly controlling
file permissions is the method to prevent such incidents in the future, but should take place once
the incident reporting and investigation activities are completed.