<< Prev Question Next Question >>

Question 90/133

Scenario 9: CoreBit Systems
CoreBit Systems, with its headquarters m San Francisco, specializes in information and communication technology (ICT) solutions, its clientele primarily includes data communication enterprises and network operators. The company's core objective is to enable its clients a smooth transition into multi-service providers, aligning their operations with the complex demands of the digital landscape.
Recently. John, the internal auditor of CoreBit Systems, conducted an internal audit which uncovered nonconformities related to their monitoring procedures and system vulnerabilities, in response to the identified nonconformities. CoreBit Systems decided to employ a comprehensive problem-solving approach to solve these issues systematically. The method encompasses a team-oriented approach, aiming to identify, correct, and eliminate the root causes of issues. This approach involves several steps. First, establish a group of experts with deep knowledge of processes and controls. Next, break down the nonconformity into measurable components and implement interim containment measures. Then, identify potential root causes and select and verify permanent corrective actions. Finally, put those actions into practice, validate them, take steps to prevent recurrence, and recognize and acknowledge the team's efforts.
Following the analysis of the root cause of the nonconformities, CoreBit Systems's ISMS project manager. Julia, developed a list of potential actions to address the identified nonconformities. Julia carefully evaluated the list to ensure that each action would effectively eliminate the root cause of the respective nonconformity. While assessing potential corrective action for addressing a nonconformity, Julia identified the issue as significant and assessed a high likelihood of its reoccurrence Consequently, she chose to implement temporary corrective actions. Afterward. Julia combined all the nonconformities Into a single action plan and sought approval from the top management.
The submitted action plan was written as follows:
A new version of the access control policy will be established and new restrictions will be created to ensure that network access is effectively managed and monitored by the Information and Communication Technology (ICT) Department.
However. Julia's submitted action plan was not approved by top management The reason cited was that a general action plan meant to address all nonconformities was deemed unacceptable. Consequently, Julia revised the action plan and submitted separate ones for approval Unfortunately, Julia did not adhere to the organization's specified deadline for submission, resulting in a delay in the corrective action process, and notably, the revised action plans lacked a defined schedule for execution.
Julia, the ISMS project manager, developed a combined action plan for all nonconformities. However, it was rejected, revised, and resubmitted late-without defined execution schedules.
Did CoreBit Systems have a plan in place to implement permanent corrective action to address the identified nonconformities?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (133q)
Question 1: Scenario 7: InfoSec, based in Boston, MA, is a multinational...
Question 2: Scenario 9: SkyFleet specializes in air freight services, pr...
Question 3: Scenario 5: Bytes iS a dynamic and innovative Company specia...
Question 4: An organization has decided to conduct information security ...
Question 5: Which of the following is NOT part of the steps required by ...
Question 6: What should an organization demonstrate through documentatio...
Question 7: How should the level of detail in risk identification evolve...
Question 8: Scenario 6: Skyver manufactures electronic products, such as...
Question 9: How can SkyFleet demonstrate its ongoing commitment to conti...
Question 10: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 11: What is the primary requirement for the documented informati...
Question 12: Which of the following standards provides the requirements a...
Question 13: Scenario 7: Yefund, an insurance Company headquartered in Mo...
Question 14: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 15: Scenario 6: CB Consulting iS a reputable firm based in Dubli...
Question 16: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 17: Scenario 3: Socket Inc. is a dynamic telecommunications comp...
Question 18: Scenario: Evergreen tailored the format and naming conventio...
Question 19: Scenario 2: Beauty is a well-established cosmetics company i...
Question 20: Scenario 4: FinSecure Finsecure is a financial institution b...
Question 21: Scenario 2: NyvMarketing is a marketing firm that provides d...
Question 22: Scenario 7: InfoSec, based in Boston, MA, is a multinational...
Question 23: Scenario 5: OperazelT is a software development company that...
Question 24: An organization has established a policy that provides the p...
Question 25: Which tool is used to identify, analyze, and manage interest...
Question 26: A manufacturing company faced a risk of production delays du...
Question 27: Scenario 4: UX Software, a company specializing in L.JXfUl d...
Question 28: Which statement is an example of risk retention?...
Question 29: Scenario 8: SunDee is a biopharmaceutical firm headquartered...
Question 30: Which statement regarding management reviews is correct?...
Question 31: Which of the following would be an acceptable justification ...
Question 32: Scenario 4: UX Software, a company specializing in L.JXfUl d...
Question 33: Scenario 4: UX Software, a company specializing in L.JXfUl d...
Question 34: A tech company rapidly expanded its operations over the past...
Question 35: Jane is a developer looking to deploy an application she cre...
Question 36: Scenario 3: Socket Inc. is a dynamic telecommunications comp...
Question 37: Which approach should organizations use to implement an ISMS...
Question 38: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 39: Scenario 3: Socket Inc. is a dynamic telecommunications comp...
Question 40: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 41: According to ISO/IEC 270G1. why shall organizations document...
Question 42: Scenario 8: BioVitalis BioVitalis is a biopharmaceutical fir...
Question 43: Which option below should be addressed in an information sec...
Question 44: What service did Auto Tsaab implement to manage and protect ...
Question 45: What risk treatment option has Company A Implemented If it h...
Question 46: Scenario 10: CircuitLinking is a company specializing in wat...
Question 47: Scenario 9: OpenTech, headquartered in San Francisco, specia...
Question 48: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 49: Which audit phase was conducted after the issue with the aud...
Question 50: Which of the following is the information security committee...
Question 51: During a security audit, analysts discover that an attacker ...
Question 52: Scenario 1: NobleFind is an online retailer specializing in ...
Question 53: Which of the following statements regarding information secu...
Question 54: An organization wants to enable the correlation and analysis...
Question 55: Scenario 10: ProEBank ProEBank is an Austrian financial inst...
Question 56: Scenario 6: GreenWave GreenWave, a manufacturer of sustainab...
Question 57: Scenario 8: SunDee is a biopharmaceutical firm headquartered...
Question 58: Scenario 7: Yefund, an insurance Company headquartered in Mo...
Question 59: Scenario 5: OperazelT is a software development company that...
Question 60: Scenario 10: ProEBank ProEBank is an Austrian financial inst...
Question 61: Scenario 4: TradeB is a newly established commercial bank lo...
Question 62: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 63: Scenario 9: OpenTech, headquartered in San Francisco, specia...
Question 64: Scenario 5: Operaze is a small software development company ...
Question 65: A small organization that is implementing an ISMS based on I...
Question 66: Scenario 8: SecureLynx is one Of the largest cybersecurity a...
Question 67: Which security controls must be implemented to comply with I...
Question 68: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 69: Scenario 9: OpenTech provides IT and communications services...
Question 70: HealthGenic is a pediatric clinic that monitors the health a...
Question 71: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 72: Which tool is used to identify, analyze, and manage interest...
Question 73: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 74: Scenario 10: CircuitLinking is a company specializing in wat...
Question 75: Scenario 9: SkyFleet specializes in air freight services, pr...
Question 76: A tech company rapidly expanded its operations over the past...
Question 77: According to ISO/IEC 27001, what shall the organization dete...
Question 78: Scenario 7: Yefund, an insurance Company headquartered in Mo...
Question 79: Upon the risk assessment outcomes. Socket Inc. decided to: *...
Question 80: Who is responsible for ensuring that the ISMS achieves its i...
Question 81: Org Y. a well-known bank, uses an online banking platform th...
Question 82: What does the organization still need to manage when using P...
Question 83: Who should be involved, among others, in the draft, review, ...
Question 84: According to ISO/IEC 27001 controls, why should the use of p...
Question 85: Scenario 3: Socket Inc is a telecommunications company offer...
Question 86: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 87: Which control in Annex A of ISO/IEC 27001 requires that the ...
Question 88: Scenario 9: OpenTech provides IT and communications services...
Question 89: Scenario 5: Operaze is a small software development company ...
Question 90: Scenario 9: CoreBit Systems CoreBit Systems, with its headqu...
Question 91: Which of the following standards provides the requirements a...
Question 92: Is NyvMarketing required to follow the guidelines of ISO/IEC...
Question 93: What is the purpose of ISO/IEC 27002:2022 Clause 8.28?...
Question 94: Scenario 5: OperazelT is a software development company that...
Question 95: The Incident Response Team (IRT) has been notified of a pote...
Question 96: Scenario 4: TradeB is a newly established commercial bank lo...
Question 97: Refer to Scenario 4 (FinSecure) Finsecure is a financial ins...
Question 98: Scenario 7: Incident Response at Texas H&amp;H Inc. Once the...
Question 99: Scenario 7: CyTekShield CyTekShield based in Dublin. Ireland...
Question 100: Whom should an organization interview to obtain information ...
Question 101: Scenario 9: OpenTech provides IT and communications services...
Question 102: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 103: Levo Corporation has implemented a demilitarized zone (DMZ) ...
Question 104: Scenario 4: UX Software, a company specializing in L.JXfUl d...
Question 105: Scenario 3: Socket Inc. is a dynamic telecommunications comp...
Question 106: Has Bytes determined all the relevant factors that impact it...
Question 107: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 108: Scenario 3: Auto Tsaab, a Swedish Car manufacturer founded i...
Question 109: Scenario 6: Skyver manufactures electronic products, such as...
Question 110: Scenario 5: Operaze is a small software development company ...
Question 111: Scenario 5: Bytes iS a dynamic and innovative Company specia...
Question 112: Scenario 1: HealthGenic is a leading multi-specialty healthc...
Question 113: Scenario 2: NyvMarketing is a marketing firm that provides d...
Question 114: In the SABSA framework, which layer is concerned with viewin...
Question 115: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 116: Scenario 1: HealthGenic is a leading multi-specialty healthc...
Question 117: Following a repotted event, an Information security event ti...
Question 118: Scenario 2: NyvMarketing is a marketing firm that provides d...
Question 119: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 120: Which of the following is the most suitable option for prese...
Question 121: The purpose of control 5.9 inventory of Information and othe...
Question 122: Scenario 1: HealthGenic is a leading multi-specialty healthc...
Question 123: What is the main purpose of Annex A 7.1 Physical security pe...
Question 124: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 125: Scenario 5: Bytes iS a dynamic and innovative Company specia...
Question 126: Scenario 8: SunDee is a biopharmaceutical firm headquartered...
Question 127: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 128: Scenario 3: Socket Inc is a telecommunications company offer...
Question 129: Why is an in-depth review crucial for organizations to evalu...
Question 130: Scenario 6: GreenWave GreenWave, a manufacturer of sustainab...
Question 131: Which of the following processes may involve increasing risk...
Question 132: An employee from Reyae Ltd. unintentionally sent an email co...
Question 133: Scenario 6: Skyver manufactures electronic products, such as...