<< Prev Question Next Question >>

Question 16/35

Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits from its clients and offers basic financial services and loans for investments. TradeB has decided to implement an information security management system (ISMS) based on ISO/IEC 27001 Having no experience of a management
[^system implementation, TradeB's top management contracted two experts to direct and manage the ISMS implementation project.
First, the project team analyzed the 93 controls of ISO/IEC 27001 Annex A and listed only the security controls deemed applicable to the company and their objectives Based on this analysis, they drafted the Statement of Applicability. Afterward, they conducted a risk assessment, during which they identified assets, such as hardware, software, and networks, as well as threats and vulnerabilities, assessed potential consequences and likelihood, and determined the level of risks based on three nonnumerical categories (low, medium, and high). They evaluated the risks based on the risk evaluation criteria and decided to treat only the high risk category They also decided to focus primarily on the unauthorized use of administrator rights and system interruptions due to several hardware failures by establishing a new version of the access control policy, implementing controls to manage and control user access, and implementing a control for ICT readiness for business continuity Lastly, they drafted a risk assessment report, in which they wrote that if after the implementation of these security controls the level of risk is below the acceptable level, the risks will be accepted What should TradeB do in order to deal with residual risks? Refer to scenario 4.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (35q)
Question 1: Scenario 3: Socket Inc is a telecommunications company offer...
Question 2: Which of the situations below can negatively affect the inte...
Question 3: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 4: Scenario 5: Operaze is a small software development company ...
Question 5: What should an organization allocate to ensure the maintenan...
Question 6: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 7: Scenario 7: InfoSec is a multinational corporation headquart...
Question 8: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 9: Del&amp;Co has decided to improve their staff-related contro...
Question 10: An employee of the organization accidentally deleted custome...
Question 11: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 12: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 13: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 14: Which approach should organizations use to implement an ISMS...
Question 15: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 16: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 17: Scenario 3: Socket Inc is a telecommunications company offer...
Question 18: An organization that has an ISMS in place conducts managemen...
Question 19: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 20: Scenario 3: Socket Inc is a telecommunications company offer...
Question 21: Scenario 9: OpenTech provides IT and communications services...
Question 22: Kyte. a company that has an online shopping website, has add...
Question 23: What supports the continual improvement of an ISMS?...
Question 24: An organization wants to enable the correlation and analysis...
Question 25: An organization has decided to conduct information security ...
Question 26: Scenario 3: Socket Inc is a telecommunications company offer...
Question 27: Which tool is used to identify, analyze, and manage interest...
Question 28: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 29: A small organization that is implementing an ISMS based on I...
Question 30: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 31: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 32: What is the main purpose of Annex A 7.1 Physical security pe...
Question 33: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 34: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 35: Which security controls must be implemented to comply with I...