Study sets
English

Information Security Management Examination (SG) | Section A Security Management and Law 04

1 / 100.0s

Problem 1 ・ Question 1 / 10

What should be done first in operating an ISMS?

View explanation

Taking the organisation's circumstances into account, make the scope and the basic policy of the ISMS clear.

Problem 1 ・ Question 2 / 10

Which team is responsible for the organisation's response to information security incidents?

View explanation

A CSIRT gathers and analyses incident information, responds and coordinates communication.

Problem 1 ・ Question 3 / 10

Which is an appropriate way to check the effectiveness of security education?

View explanation

Measure comprehension and changes in behaviour, and improve the content of the education according to the results.

Problem 1 ・ Question 4 / 10

In managing the security of a subcontractor, what should be done before the contract?

View explanation

According to the importance of the information entrusted, confirm the subcontractor's management capability at the selection stage.

Problem 1 ・ Question 5 / 10

What should an organisation that has outsourced work involving personal data do?

View explanation

The outsourcing organisation is required to supervise properly how the subcontractor handles personal data.

Problem 1 ・ Question 6 / 10

Which law relates to the act of using someone else's ID and password without permission to break into an access-controlled system?

View explanation

Unauthorised access using another person's identification code falls under that Act.

Problem 1 ・ Question 7 / 10

Which is among the requirements for protection as a trade secret?

View explanation

A trade secret must be managed as secret, be useful and not be publicly known.

Problem 1 ・ Question 8 / 10

Which is appropriate access management when an employee leaves the company?

View explanation

Remove unnecessary rights promptly when people leave or change roles.

Problem 1 ・ Question 9 / 10

Which is the most appropriate evidence for an information security audit?

View explanation

Audit conclusions rest on sufficient and appropriate evidence that can be confirmed objectively.

Problem 1 ・ Question 10 / 10

What is the main purpose of setting out contacts and the division of roles in an incident response plan?

View explanation

Deciding the chain of command and the lines of communication in advance keeps down confusion in the first response.