<< Prev Question Next Question >>

Question 17/27

Scenario 4: In 2017, seeing that millions of people turned to online shopping, Ed and James Cordon founded the online marketplace for footwear called Poshoe. In the past, purchasing pre-owned designer shoes online was not a pleasant experience because of unattractive pictures and an inability to ascertain the products' authenticity. However, after Poshoe's establishment, each product was well advertised and certified as authentic before being offered to clients. This increased the customers' confidence and trust in Poshoe's products and services. Poshoe has approximately four million users and its mission is to dominate the second-hand sneaker market and become a multi-billion dollar company.
Due to the significant increase of daily online buyers, Poshoe's top management decided to adopt a big data analytics tool that could help the company effectively handle, store, and analyze dat a. Before initiating the implementation process, they decided to conduct a risk assessment. Initially, the company identified its assets, threats, and vulnerabilities associated with its information systems. In terms of assets, the company identified the information that was vital to the achievement of the organization's mission and objectives. During this phase, the company also detected a rootkit in their software, through which an attacker could remotely access Poshoe's systems and acquire sensitive data.
The company discovered that the rootkit had been installed by an attacker who had gained administrator access. As a result, the attacker was able to obtain the customers' personal data after they purchased a product from Poshoe. Luckily, the company was able to execute some scans from the target device and gain greater visibility into their software's settings in order to identify the vulnerability of the system.
The company initially used the qualitative risk analysis technique to assess the consequences and the likelihood and to determine the level of risk. The company defined the likelihood of risk as "a few times in two years with the probability of 1 to 3 times per year." Later, it was decided that they would use a quantitative risk analysis methodology since it would provide additional information on this major risk. Lastly, the top management decided to treat the risk immediately as it could expose the company to other issues. In addition, it was communicated to their employees that they should update, secure, and back up Poshoe's software in order to protect customers' personal information and prevent unauthorized access from attackers.
According to scenario 4, the top management of Poshoe decided to treat the risk immediately after conducting the risk analysis. Is this in compliance with risk management best practices?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (27q)
Question 1: After creating a plan for outsourcing to a cloud service pro...
Question 2: Based on NIST Risk Management Framework, what is the last st...
Question 3: Scenario 6: Productscape is a market research company headqu...
Question 4: Scenario 5: Detika is a private cardiology clinic in Pennsyl...
Question 5: An organization has installed security cameras and alarm sys...
Question 6: Scenario 3: Printary is an American company that offers digi...
Question 7: Scenario 4: In 2017, seeing that millions of people turned t...
Question 8: Scenario 2: Travivve is a travel agency that operates in mor...
Question 9: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 10: Scenario 7: Adstry is a business growth agency that speciali...
Question 11: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 12: Scenario 2: Travivve is a travel agency that operates in mor...
Question 13: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 14: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 15: What are opportunities?
Question 16: Scenario 6: Productscape is a market research company headqu...
Question 17: Scenario 4: In 2017, seeing that millions of people turned t...
Question 18: According to ISO 31000, which of the following is a principl...
Question 19: Scenario 3: Printary is an American company that offers digi...
Question 20: Scenario 2: Travivve is a travel agency that operates in mor...
Question 21: Based on the EBIOS RM method, which of the following is one ...
Question 22: Which activity below is NOT included in the information secu...
Question 23: Which of the following statements best defines information s...
Question 24: Scenario 3: Printary is an American company that offers digi...
Question 25: Scenario 4: In 2017, seeing that millions of people turned t...
Question 26: An organization decided to use nonnumerical categories, i.e....
Question 27: Scenario 8: Biotide is a pharmaceutical company that produce...