Question 1 of 30
SecureBank, a multinational financial institution, is implementing a continuous authentication system within its mobile banking application using facial recognition. Initial user enrollment involves capturing a facial biometric template. After six months, several users report increasing difficulty logging in, despite no intentional changes to their appearance. The bank\'s security team discovers that the facial recognition system\'s False Rejection Rate (FRR) has significantly increased for these users. The Chief Information Security Officer (CISO) proposes automatically updating the biometric templates every three months to mitigate the FRR issue. However, the bank\'s legal counsel raises concerns about compliance with international data privacy regulations and the ethical implications of long-term biometric data retention. Considering the need for robust security, optimal user experience, and adherence to ethical data handling practices, what is the MOST appropriate strategy for SecureBank to adopt regarding biometric template management in this scenario?
Implement a hybrid approach involving periodic template updates triggered by performance degradation (e.g., FRR exceeding a threshold) coupled with explicit user consent for each update, alongside robust data governance policies defining data retention and deletion protocols.
Automatically update biometric templates every three months for all users, regardless of performance, to ensure optimal accuracy and minimize the FRR, while relying on the bank's existing privacy policy as sufficient user notification.
Discontinue the use of facial recognition for continuous authentication and revert to traditional password-based authentication to avoid potential data privacy violations and ethical concerns.
Retain the original biometric templates indefinitely without updates, but implement a multi-factor authentication system that requires users to verify their identity through secondary methods, such as SMS codes, when the FRR exceeds a certain threshold.