nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #53

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. Your colleague…

The correct answer is E. A contractor who has not been paid deletes top management ICT accounts F. An unhappy employee changes payroll records without permission H. The organisation's marketing data is copied by hackers and sold to a competitor. According to ISO/IEC 27000:2018, which provides an overview and vocabulary of information security management systems, an information security event is an identified occurrence of a system, service or network state indicating a possible breach of information security policy or…

ISO/IEC 27001 Controls

Question

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. Your colleague seems unsure as to the difference between an information security event and an information security incident. You attempt to explain the difference by providing examples. Which three of the following scenarios can be defined as information security incidents?

Options

  • AThe organisation's malware protection software prevents a virus
  • BA hard drive is used after its recommended replacement date
  • CThe organisation receives a phishing email
  • DAn employee fails to clear their desk at the end of their shift
  • EA contractor who has not been paid deletes top management ICT accounts
  • FAn unhappy employee changes payroll records without permission
  • GThe organisation fails a third-party penetration test
  • HThe organisation's marketing data is copied by hackers and sold to a competitor

How the community answered

(18 responses)
  • B
    6% (1)
  • C
    6% (1)
  • E
    72% (13)
  • G
    17% (3)

Explanation

According to ISO/IEC 27000:2018, which provides an overview and vocabulary of information security management systems, an information security event is an identified occurrence of a system, service or network state indicating a possible breach of information security policy or failure of safeguards, or a previously unknown situation that may be security relevant1. An information security incident is a single or a series of unwanted or unexpected information security events that have a significant probability of compromising business operations and threatening information security1. Therefore, based on this definition, three examples of information security incidents are: A contractor who has not been paid deletes top management ICT accounts: This is an example of an unwanted or unexpected information security event that has a significant probability of compromising business operations and threatening information security, as it may result in loss of access, data, or functionality for the top management. An unhappy employee changes payroll records without permission: This is an example of an unwanted or unexpected information security event that has a significant probability of compromising business operations and threatening information security, as it may result in financial fraud, legal liability, or reputational damage for the organization. The organisation's marketing data is copied by hackers and sold to a competitor: This is an example of an unwanted or unexpected information security event that has a significant probability of compromising business operations and threatening information security, as it may result in loss of confidentiality, competitive advantage, or customer trust for the

Topics

#information security incidents#security events vs incidents#incident classification#ISO/IEC 27035

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice