Skip to content

Performance Management · Management information systems

Data Security, Governance and Ethics for ACCA PM

Updated 11 October 2026 · Fact-checked

Data security protects information from loss, theft, misuse and error. You identify the threat, then match it with a control: physical, logical, procedural or legal. Governance sets who owns and may use data. Ethics asks whether using large data sets is fair, lawful and transparent to the people concerned.

Understand Data Security, Governance and Ethics

Data is a valuable asset. If it is lost, altered or leaked, the business can suffer financial loss, fines, legal action and damaged reputation. Management information is only useful if it is accurate, complete and available to the right people. Security protects those qualities.

Start with the risks. Some are external: hacking, malware, ransomware, phishing and denial-of-service attacks. Some are internal: staff error, fraud, weak passwords, careless sharing and disgruntled employees. Others are physical or technical: fire, flood, theft of devices, power failure and system crashes. Loss of data is often an accident, not an attack.

Then match controls to the risk. Think in groups. Physical controls include locked server rooms, ID badges and secure disposal of devices. Logical controls include passwords, multi-factor authentication, user access levels, encryption, firewalls, anti-malware and audit trails. Procedural controls include backups, a disaster recovery plan, staff training, segregation of duties, and policies on removable media and remote working. Controls cost money and slow people down, so their cost should be proportionate to the risk.

Governance is about who is accountable for data. It covers data ownership, quality standards, access rights, retention periods and how data is deleted. Good governance also means following data protection law. Laws differ by country, but common principles are that personal data is used lawfully, for a stated purpose, kept accurate, kept only as long as needed, and held securely. Individuals often have rights to see and correct their data.

Ethics goes beyond the law. With big data and analytics, organisations can profile customers and staff in detail. Ethical questions include privacy, consent, transparency about use, bias in algorithms, discrimination, and whether data collected for one purpose is reused for another. A legal action may still be ethically poor. Link to ACCA's ethical principles: integrity, objectivity, professional competence and due care, confidentiality and professional behaviour.

Key rules to remember

Risk-to-control matching
Threat → Control type → Specific control
Name the threat first, then say whether the control is physical, logical or procedural, then give the specific measure.
Security aims (CIA)
Confidentiality + Integrity + Availability
Confidentiality: only authorised people see data. Integrity: data is accurate and unaltered. Availability: data is accessible when needed.
Common data protection principles
Lawful use, stated purpose, minimum necessary, accurate, limited retention, secure
Use as a checklist for governance. Name the exact law only if the question gives it.
Control cost test
Cost of control ≤ expected loss avoided
A rule of thumb for judging controls. Include non-financial losses such as reputation.

How to solve Data Security, Governance and Ethics questions

Use this approach for any written or objective question on data security, governance or ethics.

  1. 1Read the scenario and identify what data is held, who uses it and how it is stored or shared.
  2. 2Decide what the question asks for: risks, controls, governance, legal issues or ethical issues.
  3. 3List the relevant threats, split into external, internal and physical or technical.
  4. 4Match each threat with a specific control and label it physical, logical or procedural.
  5. 5Add governance points: ownership, access rights, retention and compliance with data protection rules.
  6. 6Raise ethical issues tied to the scenario: privacy, consent, transparency, bias and purpose of use.
  7. 7Weigh the cost and practicality of the controls, and note that no control removes all risk.
  8. 8Finish with a short recommendation that applies to the business in the question.

Quickest way: Threat, control, consequence

When to use it: Use for Section A and B objective questions and for planning short Section C answers.

  1. Underline the threat in the question.
  2. Ask which of confidentiality, integrity or availability is at risk.
  3. Pick the control that directly stops that threat, not a general one.
  4. For ethics questions, ask whether the people affected know and agree.
  5. Eliminate options that are true in general but do not fit the scenario.

Common mistakes in Data Security, Governance and Ethics

  • Listing generic controls such as 'use passwords' for every scenario.

    Students memorise a list and do not read the scenario.

    Fix: Tie each control to the specific threat and the data in the question.

  • Confusing security, governance and ethics.

    All three deal with data, so they seem the same.

    Fix: Security protects data, governance sets rules and accountability, ethics judges whether use is fair. Label each point.

  • Treating legal compliance as the same as ethical behaviour.

    Students assume anything lawful is acceptable.

    Fix: State that an action can be lawful but still unfair, such as intrusive profiling without clear consent.

  • Ignoring internal threats.

    Hackers feel more dramatic than staff error.

    Fix: Always include employee error, fraud and misuse, with controls like access levels, training and segregation of duties.

  • Claiming a control removes the risk completely.

    Students want a neat answer.

    Fix: Say controls reduce risk. Mention residual risk and the cost of the control.

  • Forgetting backups and recovery when availability is the issue.

    Focus stays on keeping outsiders out.

    Fix: For loss or downtime, name backups, off-site storage and a tested disaster recovery plan.

Worked examples

Example 1

A retail company stores customer card details and purchase history on a central database. Staff in many branches can access it. Identify two risks and recommend a control for each.

Show the solution
  1. Data held: sensitive customer and payment data, accessed widely.
  2. Risk 1: unauthorised internal access or misuse because many staff can reach the data. This threatens confidentiality.
  3. Control 1: logical control. Restrict access by job role, require multi-factor authentication and keep an audit trail of who views records.
  4. Risk 2: external attack such as hacking or malware stealing the data. This threatens confidentiality and integrity.
  5. Control 2: logical control. Encrypt stored data, use firewalls and up-to-date anti-malware, and test security regularly.
  6. Note that controls cost money, but a breach could bring fines, lost customers and reputational harm, so the spend is justified.

Answer: Risk 1: internal misuse, controlled by role-based access, multi-factor authentication and audit trails. Risk 2: external attack, controlled by encryption, firewalls and anti-malware.

Example 2

A bank plans to use big data analytics on customers' spending patterns to set individual loan prices. Discuss the ethical issues.

Show the solution
  1. Privacy: detailed spending data reveals private lifestyle details. Customers may not expect it to be used for pricing.
  2. Consent and transparency: the bank should tell customers what data is used and why, and get agreement where required.
  3. Purpose: data collected to run accounts is being reused for a different purpose. This needs a lawful basis and a clear explanation.
  4. Bias and fairness: algorithms may reflect past bias and disadvantage certain groups unfairly. Models should be tested and reviewed by people.
  5. Accuracy: errors in data could lead to wrongly high prices, so customers need a way to see and correct their data.
  6. Security and governance: the data must be held securely, with named owners, limited access and defined retention.
  7. Conclude that the plan may be lawful but should proceed only with transparency, fairness checks and strong governance.

Answer: Key issues are privacy, consent, reuse of data for a new purpose, algorithmic bias, accuracy and security. The bank should be transparent, test for bias, allow correction of data and apply strong governance.

Exam tips

  • In Section C, structure answers under clear labels such as risks, controls, governance and ethics. It makes marks easy to find.
  • For objective questions, match the control to the exact threat. Wrong options are often real controls that fit a different threat.
  • Always link points to the scenario's business, data and users. Generic lists score poorly.
  • Use ACCA's ethical principles when discussing professional behaviour, especially confidentiality and integrity.
  • Do not quote a specific law's details unless the question provides them. Describe the principles instead.

Practice questions from Management information systems

Data Security, Governance and Ethics in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Data Security, Governance and Ethics: frequently asked questions

What are the main data security risks in ACCA PM?

They include hacking, malware, phishing, staff error, fraud, theft of devices and system failure. Group them as external, internal and physical or technical. Then give a control for each.

What is the difference between data governance and data security?

Data security is the set of measures that protect data from threats. Governance is the framework of ownership, rules, quality standards and accountability for how data is used and kept. Security is one part of good governance.

What ethical issues arise with big data?

Main issues are privacy, consent, transparency, bias in algorithms, discrimination and reuse of data for new purposes. Even lawful use can be unethical if it is unfair or hidden from the people affected.

Do I need to know specific data protection laws?

Usually you only need the general principles, such as lawful use, stated purpose, accuracy, limited retention and security. Apply any law named in the question rather than recalling detailed provisions.