41.8k views
3 votes
Message 1

I am escalating a security issue for ProjectX, which is an initiative to deliver exciting features to customers....

Message 2
It has come to my attention that ProjectX has a security vulnerability. The storage module does not encrypt sensitive customer details.....

Message 3
ProjectX is not encrypting customer data!...

Message 4
As you may be aware, ProjectX is our new flagship customer banking platform in development...

A security architect is working with a project team to deliver an important service that stores and processes customer banking details. The project, internally known as ProjectX, is due to launch its first set of features publicly within a week, but the team has not been able to implement encryption-at-rest of the customer records.The security architect is drafting an escalation email to senior leadership.

Which of the following BEST conveys the business impact for senior leadership?

A. Message 1
B. Message 2
C. Message 3
D. Message 4

User Jape
by
7.9k points

1 Answer

2 votes

Final answer:

Message 2 is the best choice to convey the business impact to senior leadership as it highlights the lack of encryption for sensitive customer details in Project X, emphasizing the necessity for online privacy and data security. So, the correct option is B. Message 2

Step-by-step explanation:

The task given requires drafting an escalation email to senior leadership to convey the business impact of a security issue in Project X.

Among the options given, Message 2 best conveys the necessary urgency and details that senior leadership would need to understand the gravity of the situation.

This message highlights that the storage module does not encrypt sensitive customer details, which is a serious concern in the context of online privacy and security.

It is essential to stress that recent data breaches have exposed millions to identity theft, emphasizing the need for data security measures such as encryption-at-rest to protect sensitive information.

The fact that ProjectX currently lacks this critical security feature could result in unauthorized access to customer banking details, potentially leading to a data breach with significant reputational and financial consequences for the organization.

Therefore, it is crucial to address this risk before launching any features to the public.

So, the correct option is B. Message 2

User Wade Tandy
by
8.1k points