A security policy forbids USB use with personal data, but the organisation has no monitoring, enforcement, or exception process. What lesson should CIPP/E candidates take about organisational measures?
Select an answer to reveal the explanation.
Short Explanation
A 'no USB' poster without checks is theater. Organisational measures have to live in the real hallway—monitoring, exceptions done right, consequences when needed. Paper policy without practice is a fridge magnet, not a control.
Full Explanation
Technical and organisational measures must be effective in practice. A formal prohibition on USB use that lacks monitoring, enforceable processes, or managed exceptions typically fails to provide appropriate protection. Controllers should implement and operate controls, not merely publish aspirational policy language.