<< Prev Question Next Question >>

Question 9/27

Scenario 8: Biotide is a pharmaceutical company that produces medication for treating different kinds of diseases. The company was founded in 1997, and since then it has contributed in solving some of the most challenging healthcare issues.
As a pharmaceutical company, Biotide operates in an environment associated with complex risks. As such, the company focuses on risk management strategies that ensure the effective management of risks to develop high-quality medication. With the large amount of sensitive information generated from the company, managing information security risks is certainly an important part of the overall risk management process. Biotide utilizes a publicly available methodology for conducting risk assessment related to information assets. This methodology helps Biotide to perform risk assessment by taking into account its objectives and mission. Following this method, the risk management process is organized into four activity areas, each of them involving a set of activities, as provided below.
1. Activity area 1: The organization determines the criteria against which the effects of a risk occurring can be evaluated. In addition, the impacts of risks are also defined.
2. Activity area 2: The purpose of the second activity area is to create information asset profiles. The organization identifies critical information assets, their owners, as well as the security requirements for those assets. After determining the security requirements, the organization prioritizes them. In addition, the organization identifies the systems that store, transmit, or process information.
3. Activity area 3: The organization identifies the areas of concern which initiates the risk identification process. In addition, the organization analyzes and determines the probability of the occurrence of possible threat scenarios.
4. Activity area 4: The organization identifies and evaluates the risks. In addition, the criteria specified in activity area 1 is reviewed and the consequences of the areas of concerns are evaluated. Lastly, the level of identified risks is determined.
The table below provides an example of how Biotide assesses the risks related to its information assets following this methodology:

Based on the table provided in scenario 8, did Biotide follow all the steps of the risk assessment methodology regarding the identification of assets?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (27q)
Question 1: After creating a plan for outsourcing to a cloud service pro...
Question 2: Based on NIST Risk Management Framework, what is the last st...
Question 3: Scenario 6: Productscape is a market research company headqu...
Question 4: Scenario 5: Detika is a private cardiology clinic in Pennsyl...
Question 5: An organization has installed security cameras and alarm sys...
Question 6: Scenario 3: Printary is an American company that offers digi...
Question 7: Scenario 4: In 2017, seeing that millions of people turned t...
Question 8: Scenario 2: Travivve is a travel agency that operates in mor...
Question 9: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 10: Scenario 7: Adstry is a business growth agency that speciali...
Question 11: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 12: Scenario 2: Travivve is a travel agency that operates in mor...
Question 13: Scenario 8: Biotide is a pharmaceutical company that produce...
Question 14: Scenario 1 The risk assessment process was led by Henry, Bon...
Question 15: What are opportunities?
Question 16: Scenario 6: Productscape is a market research company headqu...
Question 17: Scenario 4: In 2017, seeing that millions of people turned t...
Question 18: According to ISO 31000, which of the following is a principl...
Question 19: Scenario 3: Printary is an American company that offers digi...
Question 20: Scenario 2: Travivve is a travel agency that operates in mor...
Question 21: Based on the EBIOS RM method, which of the following is one ...
Question 22: Which activity below is NOT included in the information secu...
Question 23: Which of the following statements best defines information s...
Question 24: Scenario 3: Printary is an American company that offers digi...
Question 25: Scenario 4: In 2017, seeing that millions of people turned t...
Question 26: An organization decided to use nonnumerical categories, i.e....
Question 27: Scenario 8: Biotide is a pharmaceutical company that produce...