An employee wants to send customer data to a public generative service.
Allow any exception only with controlled risk.
Choose two governance practices.
Define permitted data, services, purposes, and retention, and require an approver, expiry, compensating controls, and audit record for exceptions.
Detailed explanation
Users can determine what is allowed.
Users can determine what is allowed.
An exception does not become an untracked permanent bypass.
An exception does not become an untracked permanent bypass.
Threats, laws, and capabilities change.
Threats, laws, and capabilities change.
Audit and incident response are impaired.
Audit and incident response are impaired.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.2のガバナンス、コンプライアンス、ポリシー管理を確認する。Expected result
ポリシーと例外を期限・責任・監査付きで管理する理由を説明できる。Key points
- Policy
- Approval
- Expiry
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.