nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #294

Scenario: After an information security incident, an organization created a comprehensive backup procedure involving regular, automated backups of all critical data to offsite storage locations. By…

The correct answer is C. Availability. The CIA Triad (Confidentiality, Integrity, and Availability) is the foundation of information security Availability ensures that data and services are accessible when needed. By implementing regular, automated backups and offsite storage, the organization ensures that critical…

Information Security Concepts

Question

Scenario:

After an information security incident, an organization created a comprehensive backup procedure involving regular, automated backups of all critical data to offsite storage locations. By doing so, which principle of information security is the organization applying in this case?

Options

  • AIntegrity
  • BConfidentiality
  • CAvailability

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    93% (40)

Explanation

The CIA Triad (Confidentiality, Integrity, and Availability) is the foundation of information security Availability ensures that data and services are accessible when needed. By implementing regular, automated backups and offsite storage, the organization ensures that critical data remains accessible even after a security incident (e.g., data loss, cyberattacks, or hardware failures). This aligns with ISO/IEC 27001:2022 Annex A Control A.8.13 (Information Backup), which emphasizes maintaining and testing backups to ensure system resilience. Integrity ensures that data remains unaltered and accurate, but backups do not inherently enforce integrity unless accompanied by checksum or validation mechanisms. Confidentiality ensures that only authorized users can access data, which is not the primary goal of a backup procedure.

Topics

#availability#CIA triad#backup procedures#business continuity

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice