Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam ISO-IEC-27001-Lead-Implementer Topic 5 Question 40 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 40
Topic #: 5
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 2:

Beauty is a well-established cosmetics company in the beauty industry. The company was founded several decades ago with a passion for creating high-quality skincare, makeup, and personal care products that enhance natural beauty. Over the years, Beauty has built a strong reputation for its innovative product offerings, commitment to customer satisfaction, and dedication to ethical and sustainable business practices.

In response to the rapidly evolving landscape of consumer shopping habits, Beauty transitioned from traditional retail to an e-commerce model. To initiate this strategy, Beauty conducted a comprehensive information security risk assessment, analyzing potential threats and vulnerabilities associated with its new e-commerce venture, aligned with its business strategy and objectives.

Concerning the identified risks, the company implemented several information security controls. All employees were required to sign confidentiality agreements to emphasize the importance of protecting sensitive customer dat

a. The company thoroughly reviewed user access rights, ensuring only authorized personnel could access sensitive information. In addition, since the company stores valuable products and unique formulas in the warehouse, it installed alarm systems and surveillance cameras with real-time alerts to prevent any potential act of vandalism.

After a while, the information security team analyzed the audit logs to monitor and track activities across the newly implemented security controls. Upon investigating and analyzing the audit logs, it was discovered that an attacker had accessed the system due to out-of-date anti-malware software, exposing customers' sensitive information, including names and home addresses. Following this, the IT team replaced the anti-malware software with a new one capable of automatically removing malicious code in case of similar incidents. The new software was installed on all workstations and regularly updated with the latest malware definitions, with an automatic update feature enabled. An authentication process requiring user identification and a password was also implemented to access sensitive information.

During the investigation, Maya, the information security manager of Beauty, found that information security responsibilities in job descriptions were not clearly defined, for which the company took immediate action. Recognizing that their e-commerce operations would have a global reach, Beauty diligently researched and complied with the industry's legal, statutory, regulatory, and contractual requirements. It considered international and local regulations, including data privacy laws, consumer protection acts, and global trade agreements.

To meet these requirements, Beauty invested in legal counsel and compliance experts who continuously monitored and ensured the company's compliance with legal standards in every market they operated in. Additionally, Beauty conducted multiple information security awareness sessions for the IT team and other employees with access to confidential information, emphasizing the importance of system and network security.

Under which category does the vulnerability identified by Maya during the incident fall into?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Aleta
1 days ago
The vulnerability identified by Maya falls under the 'Organization' category. Clearly, the job descriptions did not clearly define information security responsibilities, which led to the security breach. The company should have had better organizational policies and structures in place to prevent such incidents.
upvoted 0 times
...
Kallie
8 days ago
I also believe it is an organizational vulnerability. Beauty should have clearly defined roles and responsibilities to prevent such incidents.
upvoted 0 times
...
Romana
12 days ago
I agree with Salina. Maya found that information security responsibilities were not clearly defined, which is an organizational issue.
upvoted 0 times
...
Salina
15 days ago
I think the vulnerability falls under the category of Organization.
upvoted 0 times
...

Save Cancel