<< Prev Question Next Question >>

Question 12/27

Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.
Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.
Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.
The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.
Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.
Did the risk management team establish all the criteria required to perform the information security risk assessment? Refer to scenario 2.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (27q)
Question 1: After creating a plan for outsourcing to a cloud service pro...
Question 2: Based on NIST Risk Management Framework, what is the last st...
Question 3: Scenario 6: Productscape is a market research company headqu...
Question 4: Scenario 5: Detika is a private cardiology clinic in Pennsyl...
Question 5: An organization has installed security cameras and alarm sys...
Question 6: Scenario 3: Printary is an American company that offers digi...
Question 7: Scenario 4: In 2017, seeing that millions of people turned t...
Question 8: Scenario 2: Travivve is a travel agency that operates in mor...
Question 9: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 10: Scenario 7: Adstry is a business growth agency that speciali...
Question 11: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 12: Scenario 2: Travivve is a travel agency that operates in mor...
Question 13: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 14: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 15: What are opportunities?
Question 16: Scenario 6: Productscape is a market research company headqu...
Question 17: Scenario 4: In 2017, seeing that millions of people turned t...
Question 18: According to ISO 31000, which of the following is a principl...
Question 19: Scenario 3: Printary is an American company that offers digi...
Question 20: Scenario 2: Travivve is a travel agency that operates in mor...
Question 21: Based on the EBIOS RM method, which of the following is one ...
Question 22: Which activity below is NOT included in the information secu...
Question 23: Which of the following statements best defines information s...
Question 24: Scenario 3: Printary is an American company that offers digi...
Question 25: Scenario 4: In 2017, seeing that millions of people turned t...
Question 26: An organization decided to use nonnumerical categories, i.e....
Question 27: Scenario 8: Biotide is a pharmaceutical company that produce...