Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam ISO-IEC-27001-Lead-Implementer Topic 2 Question 27 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 27
Topic #: 2
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 5: Operaze is a small software development company that develops applications for various companies around the world. Recently, the company conducted a risk assessment to assess the information security risks that could arise from operating in a digital landscape. Using different testing methods, including penetration Resting and code review, the company identified some issues in its ICT systems, including improper user permissions, misconfigured security settings, and insecure network configurations. To resolve these issues and enhance information security, Operaze decided to implement an information security management system (ISMS) based on ISO/IEC 27001.

Considering that Operaze is a small company, the entire IT team was involved in the ISMS implementation project. Initially, the company analyzed the business requirements and the internal and external environment, identified its key processes and activities, and identified and analyzed the interested parties In addition, the top management of Operaze decided to Include most of the company's departments within the ISMS scope. The defined scope included the organizational and physical boundaries. The IT team drafted an information security policy and communicated it to all relevant interested parties In addition, other specific policies were developed to elaborate on security issues and the roles and responsibilities were assigned to all interested parties.

Following that, the HR manager claimed that the paperwork created by ISMS does not justify its value and the implementation of the ISMS should be canceled However, the top management determined that this claim was invalid and organized an awareness session to explain the benefits of the ISMS to all interested parties.

Operaze decided to migrate Its physical servers to their virtual servers on third-party infrastructure. The new cloud computing solution brought additional changes to the company Operaze's top management, on the other hand, aimed to not only implement an effective ISMS but also ensure the smooth running of the ISMS operations. In this situation, Operaze's top management concluded that the services of external experts were required to implement their information security strategies. The IT team, on the other hand, decided to initiate a change in the ISMS scope and implemented the required modifications to the processes of the company.

Based on the scenario above, answer the following question:

What led Operaze to implement the ISMS?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

Salley
18 days ago
Wait, I got it! Operaze is a small company, so they probably wanted to implement the ISMS to look more legit and impress their clients. You know, the whole 'ISO certification' thing.
upvoted 0 times
...
Lemuel
20 days ago
Nah, man, it's definitely A. Operaze didn't just want to identify threats, they wanted to fix the actual security problems they found. That's why they went with an ISMS.
upvoted 0 times
...
Mammie
21 days ago
Hmm, I'm not sure. Could it be B) Identification of threats? After all, Operaze is operating in a digital landscape, so they probably wanted to address potential threats as well.
upvoted 0 times
Judy
4 days ago
B) Identification of threats
upvoted 0 times
...
Shaun
9 days ago
A) Identification of vulnerabilities
upvoted 0 times
...
...
Truman
29 days ago
I agree, A is the right answer. Operaze conducted a risk assessment and identified security issues in their ICT systems, which necessitated the implementation of an ISMS.
upvoted 0 times
...
Mona
1 months ago
The correct answer is A) Identification of vulnerabilities. Operaze identified issues like improper user permissions, misconfigured security settings, and insecure network configurations, which led them to implement an ISMS to address these vulnerabilities.
upvoted 0 times
Iraida
2 days ago
C) Identification of assets
upvoted 0 times
...
Brigette
5 days ago
B) Identification of threats
upvoted 0 times
...
Tonja
24 days ago
A) Identification of vulnerabilities
upvoted 0 times
...
...
Antonio
2 months ago
Yes, I agree. By identifying vulnerabilities, Operaze realized the importance of enhancing their information security.
upvoted 0 times
...
Shelton
2 months ago
I think Operaze implemented the ISMS because they identified vulnerabilities in their ICT systems.
upvoted 0 times
...
Mollie
2 months ago
A) Identification of vulnerabilities
upvoted 0 times
...
Delmy
2 months ago
Yes, having vulnerabilities in their systems could pose a risk to their information security, so it makes sense for them to implement an ISMS.
upvoted 0 times
...
Dan
2 months ago
I think Operaze implemented the ISMS because they identified vulnerabilities in their ICT systems.
upvoted 0 times
...
Yan
2 months ago
A) Identification of vulnerabilities
upvoted 0 times
...

Save Cancel