Karinoya Learning Room

Qualifications · Information Security Management (SG) Success Lab

Information Security Management

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Information assets

Which of the following most appropriately describes an information asset in the context of information security?

  1. It refers only to information equipment such as servers and PCs and the electronic data stored inside them, and does not include printed documents kept on paper.
  2. It refers only to digitized data, excluding paper documents and the procedures or know-how known only to specific staff.
  3. It broadly includes data, documents, equipment, and software, as well as things valuable to the organization such as the knowledge people hold and the company's reputation.
  4. Only things whose value can be estimated in monetary terms count as information assets; things that cannot be converted to a monetary value, such as trust or brand, are outside the scope of management.
AnswerC. It broadly includes data, documents, equipment, and software, as well as things valuable to the organization such as the knowledge people hold and the company's reputation.

An information asset is anything worth protecting, and this includes not just data, documents, equipment, and software but also intangible assets such as the knowledge and know-how people hold and the organization's trust or brand. Narrowing the scope to only equipment, only electronic data, or only what can be converted to a monetary value leaves the excluded part as a weak point, so each of these is wrong.

Q2 | The asset inventory

Which of the following is not an appropriate item to record in an information asset inventory?

  1. The asset's name and the name of the person responsible for managing it (its owner)
  2. The actual password of the user who accesses that asset
  3. The storage location and the type of medium it is recorded on
  4. The information's confidentiality level and its business-importance classification
AnswerB. The actual password of the user who accesses that asset

Because many people refer to the inventory, writing the actual password into it means a leak of the inventory directly leads to unauthorized access. The asset name, the person responsible for managing it, the storage location, the medium, and the confidentiality and importance classifications are the basic items recorded in the inventory to decide on controls.

Q3 | Classification labels

What is the main purpose of classifying and labeling information as confidential, internal-use-only, public, and so on?

  1. So that whoever handles the information can judge how much protection it needs.
  2. To reduce the disk capacity needed to store the information and cut storage costs.
  3. To eliminate the need for classification and labeling altogether by encrypting all information.
  4. To eliminate the need to collect and keep access logs.
AnswerA. So that whoever handles the information can judge how much protection it needs.

Because a label exists, a user can judge for themselves questions like “may this be attached to an email?” or “may this be taken outside?” Classification is not a means of reducing storage capacity, classification is still needed even if information is encrypted, and labeling does not make collecting logs unnecessary, so the other choices are wrong.

Q4 | The asset owner

Which of the following is the most appropriate role of the manager responsible for an information asset (the asset's owner)?

  1. Auditing the organization's ISMS from a third-party standpoint and reporting a judgment on whether certification should be granted.
  2. Operating the asset day to day, handling tasks such as entering and updating data as part of daily work.
  3. Deciding the asset's classification, approving who is granted what level of access, and reviewing this periodically.
  4. Actually carrying out configuration changes to network equipment or servers.
AnswerC. Deciding the asset's classification, approving who is granted what level of access, and reviewing this periodically.

The manager responsible for an asset bears responsibility for deciding its classification, approving access rights, and periodically reviewing them. Day-to-day data entry is a user's job, equipment configuration is a system administrator's job, and third-party auditing is the role of a certification body; none of these is the responsible manager's role.

Q5 | Disposing of a hard disk

A company is outsourcing the disposal of an internal hard disk from a PC it used internally to an outside vendor. From the standpoint of preventing an information leak, which response is most appropriate?

  1. Move the target files to the recycle bin, empty it, confirm on screen that they have been deleted, and then hand the disk to the vendor.
  2. Run a quick format, confirm on screen that the files have disappeared, and hand the disk to the vendor as-is.
  3. Delete only the important files, leave the rest as they are, and hand the disk over.
  4. Perform overwrite erasure with data-wiping software or physical destruction, and confirm it either by witnessing the work or by receiving a certificate of erasure.
AnswerD. Perform overwrite erasure with data-wiping software or physical destruction, and confirm it either by witnessing the work or by receiving a certificate of erasure.

Emptying the recycle bin or running a quick format only clears the management information, and the data can sometimes still be recovered with recovery software. What is reliable is overwrite erasure or physical destruction, and when outsourcing the work, keeping evidence it was carried out, whether by witnessing it or through a certificate, is essential. Deleting only some of the files is out of the question.

Q6 | Disposing of paper

Which of the following is the most appropriate way to dispose of a paper document classified as internal-use-only?

  1. Tear it in half and put it out together with recyclables.
  2. Put it out mixed in with general trash so it is harder for outsiders to notice.
  3. Black out only the title, then put it out as-is.
  4. Shred it, or outsource it for pulping.
AnswerD. Shred it, or outsource it for pulping.

The basic rule for disposing of paper is to make it impossible to reconstruct, using shredding or pulping. Mixing it with other trash still leaves it readable if someone takes it out, and merely tearing it in half or blacking out the title leaves the body legible, so none of these is an appropriate way to dispose of an internal-use-only document.

Q7 | Taking inventory

Which of the following is the most appropriate reason for periodically taking inventory of information assets?

  1. To negotiate down the purchase price of information assets and keep down the cost of procuring or replacing equipment.
  2. To eliminate any gap between what the inventory records and the assets that actually exist, so that controls are applied without gaps.
  3. To make sure the total number of information assets the organization holds is reduced every single year, lightening the management burden.
  4. To track employees' work attendance and review staff assignments.
AnswerB. To eliminate any gap between what the inventory records and the assets that actually exist, so that controls are applied without gaps.

The purpose of taking inventory is to bring the inventory in line with reality. An asset not in the inventory receives no controls, and an already-disposed-of asset left in the inventory ends up being tracked pointlessly as missing. Negotiating prices and managing attendance are not the purpose, and reducing the asset count is not the purpose either.

Q8 | The information lifecycle

Viewing the information lifecycle as creation → use → storage → transfer → disposal, which of the following is the most appropriate set of controls for each stage?

  1. If transfer is done using internal courier, the handover record can be omitted.
  2. Since information in storage is kept inside the company and is safe, setting access rights is not particularly necessary.
  3. Do not decide a classification at the creation stage; only decide the classification and handling all together once it is time to dispose of the information.
  4. Lock away or encrypt information during storage; seal it and keep a handover record during transfer; and erase it or physically destroy it at disposal.
AnswerD. Lock away or encrypt information during storage; seal it and keep a handover record during transfer; and erase it or physically destroy it at disposal.

Deciding the classification at creation (acquisition) is precisely what determines how the information is handled from then on. Even while in storage, information must be protected from employees without authorization, and even for internal courier a record of who handed it over and when is still necessary. The choice that applies the right control at each stage is correct.

Q9 | Classification criteria

Which of the following is the most appropriate way of thinking when deciding an information classification level?

  1. Decide purely by the medium it is recorded on — for example, treating every electronic file as confidential and every paper document as internal-use-only.
  2. The more people in the department that created the information, the higher its classification should be.
  3. Decide it based not only on the impact of a leak, but also on the impact of tampering or of the information becoming unavailable.
  4. Once an information classification is decided, keep using it as-is afterward without review, even if the content or circumstances change.
AnswerC. Decide it based not only on the impact of a leak, but also on the impact of tampering or of the information becoming unavailable.

Classification should be decided by looking not just at confidentiality but also at the impact if integrity or availability is compromised. The number of people in the department has nothing to do with the size of the impact, and deciding uniformly by medium alone does not match reality either. A review is also needed as circumstances change, such as information whose planned publication date has passed.

Q10 | The sequence

Which of the following correctly orders the three activities that make up risk assessment, in the sequence they are carried out?

  1. Risk evaluation → risk analysis → risk identification
  2. Risk identification → risk evaluation → risk analysis
  3. Risk identification → risk analysis → risk evaluation
  4. Risk analysis → risk identification → risk evaluation
AnswerC. Risk identification → risk analysis → risk evaluation

Risk assessment is carried out in the order of identification, which finds risks; analysis, which estimates their size; and evaluation, which compares that size against a criterion to decide whether a response is needed. Something that has not been identified cannot be analyzed, and something that has not been analyzed cannot be compared against a criterion, so no other order works.

Q11 | Which activity

The team identified and wrote down the following in a list: “The server room is on the first floor, and heavy rain could flood it and stop the servers.” Which activity of risk assessment does this work correspond to?

  1. Risk treatment
  2. Risk acceptance
  3. Risk identification
  4. Risk evaluation
AnswerC. Risk identification

The activity of discovering and describing what risks exist is risk identification. Comparing the size against a risk criterion to decide whether a response is needed is risk evaluation, taking action such as avoidance or reduction is risk treatment, and accepting something as within the criteria is risk acceptance; each of these is an activity that comes after this stage.

Q12 | Where evaluation fits

Which of the following most appropriately describes risk evaluation within risk assessment?

  1. Comparing the size of risk found through analysis against a risk criterion to decide whether a response is needed and in what priority order.
  2. Comprehensively finding and describing the risks present in the organization from combinations of information assets, threats, and vulnerabilities.
  3. Actually introducing the chosen controls, putting them into operation, and embedding them into practice.
  4. Estimating the likelihood of occurrence and the degree of impact separately, and computing the size of the risk from them.
AnswerA. Comparing the size of risk found through analysis against a risk criterion to decide whether a response is needed and in what priority order.

Risk evaluation is the final activity of the assessment, the stage where the analysis results are judged against a criterion. Finding risks is risk identification, computing the size is risk analysis, and introducing controls is carrying out risk treatment; each belongs to a different stage.

Q13 | Transfer

An organization took out cyber insurance to prepare for the compensation and investigation costs that would arise from an information leak. Which category of risk treatment is this?

  1. Risk avoidance
  2. Risk reduction (mitigation)
  3. Risk acceptance (retention)
  4. Risk transfer (sharing)
AnswerD. Risk transfer (sharing)

Taking out insurance shares the burden of loss with an insurance company, so it is risk transfer (sharing). Avoidance is stopping the activity that causes the risk altogether, reduction is lowering the likelihood or impact through countermeasures, and acceptance is taking on the risk as-is without countermeasures; insurance is none of these.

Q14 | Computing ALE

A certain incident causes a loss of 6 million yen each time it occurs, and is expected to occur once every two years. What is the annualized loss expectancy (ALE) for this incident?

  1. 1,500,000 yen
  2. 3 million yen
  3. 6 million yen
  4. 12 million yen
AnswerB. 3 million yen

ALE is computed as SLE (the loss per occurrence) × ARO (the annual rate of occurrence). Once every two years means an ARO of 0.5, so 6,000,000 × 0.5 = 3,000,000 yen. 6 million yen is simply the SLE, 12 million yen is the value if it occurred twice a year, and 1,500,000 yen is the mistaken result of using an ARO of 0.25.

Q15 | Computing ALE

A disaster causes a loss of 40 million yen each time it occurs, and its annual probability is estimated at 5%. What is the annualized loss expectancy (ALE) for this disaster?

  1. 8 million yen
  2. 2 million yen
  3. 40 million yen
  4. 4 million yen
AnswerB. 2 million yen

An annual rate of 5% is an ARO of 0.05, so ALE = 40,000,000 × 0.05 = 2,000,000 yen. 4 million yen is the value using a probability of 10%, 8 million yen uses 20%, and 40 million yen is simply the SLE; each of these either fails to multiply by the annual rate of occurrence or uses the wrong one.

Q16 | Cost-effectiveness

A certain risk causes a loss of 10 million yen each time it occurs, and its annual rate of occurrence is estimated at 0.4. Introducing a countermeasure that costs 2.2 million yen a year would lower the annual rate of occurrence to 0.1. Which of the following is the most appropriate financial evaluation?

  1. The countermeasure brings the annualized loss expectancy from 10 million yen down to 1 million yen, a reduction of 9 million yen, which greatly exceeds the cost, so it is worth it.
  2. The countermeasure brings the annualized loss expectancy from 4 million yen down to 1 million yen, a reduction of 2 million yen, which falls short of the 2,200,000 yen cost, so it is not worth it.
  3. The countermeasure brings the annualized loss expectancy from 4 million yen down to 1 million yen, a reduction of 3 million yen, which exceeds the 2,200,000 yen cost, so it is worth it.
  4. Since the annual rate of occurrence has not been brought to zero, the effect of the countermeasure cannot be evaluated in monetary terms.
AnswerC. The countermeasure brings the annualized loss expectancy from 4 million yen down to 1 million yen, a reduction of 3 million yen, which exceeds the 2,200,000 yen cost, so it is worth it.

The ALE before the countermeasure is 10,000,000 × 0.4 = 4,000,000 yen, and after it is 10,000,000 × 0.1 = 1,000,000 yen, a reduction of 3,000,000 yen. Since this exceeds the 2,200,000 yen cost, it is financially reasonable. 10 million yen is the SLE, not the ALE, and treating the reduction as 2 million yen is also a computational error. A monetary comparison remains possible even when some residual risk is left over.

Q17 | Avoidance

A mail-order business that handles a large volume of personal information but shows no prospect of profitability was judged to carry too great an impact if a leak occurred, and the company withdrew from the business itself. Which category of risk treatment is this?

  1. Risk avoidance
  2. Risk transfer (sharing)
  3. Risk acceptance (retention)
  4. Risk reduction (mitigation)
AnswerA. Risk avoidance

A response that stops the activity causing the risk altogether is risk avoidance. Transfer means sharing the loss through insurance or outsourcing, reduction means lowering the likelihood or impact through countermeasures, and acceptance means taking on the risk without countermeasures; discontinuing the activity is none of these.

Q18 | Reduction

To address the risk of malware infection, an organization introduced antivirus software, thoroughly applied OS updates, and trained employees, lowering the probability of infection. Which category of risk treatment is this?

  1. Risk acceptance (retention)
  2. Risk reduction (mitigation)
  3. Risk avoidance
  4. Risk transfer (sharing)
AnswerB. Risk reduction (mitigation)

A response that carries out controls to lower the likelihood or impact is risk reduction. Avoidance means stopping the business activity itself, transfer means sharing the loss with others through insurance or outsourcing, and acceptance means taking no countermeasures because it falls within the criteria, so taking action to lower the probability is none of these.

Q19 | Acceptance

For a temporary outage of the internal bulletin board, it was confirmed that the impact on operations was small and the expected loss fell within the risk acceptance criteria, so, with the responsible manager's approval, the decision was made not to take any further countermeasure. Which category of risk treatment is this?

  1. Risk transfer (sharing)
  2. Risk avoidance
  3. Risk reduction (mitigation)
  4. Risk acceptance (retention)
AnswerD. Risk acceptance (retention)

A response that confirms the impact is small and within the acceptance criteria, and deliberately accepts it without taking a countermeasure, is risk acceptance (retention). Avoidance is stopping the activity, transfer is sharing the loss, and reduction is carrying out a countermeasure; each of these differs from acceptance in that some action is taken. Note that this is not simply neglect — the responsible manager's approval and a record are required.

Q20 | Treatments and examples

Which combination of a risk treatment category and a concrete example is not appropriate?

  1. Risk acceptance — a loss severe enough to threaten business continuity would occur, but doing nothing because a countermeasure is too much trouble.
  2. Risk avoidance — discontinuing an online service judged too dangerous and withdrawing from that business.
  3. Risk transfer — taking out insurance in case of an information leak, having the insurance company bear part of the loss.
  4. Risk reduction — encrypting important data and periodically taking backups stored in a separate location.
AnswerA. Risk acceptance — a loss severe enough to threaten business continuity would occur, but doing nothing because a countermeasure is too much trouble.

Acceptance is a response chosen after confirming the impact is small and within the acceptance criteria, and approved by the responsible manager; neglecting a risk severe enough to threaten business continuity simply because a countermeasure is a hassle is not acceptance. The other three combinations — insurance as transfer, discontinuing a service as avoidance, and encryption or backups as reduction — are correct.

Q21 | Residual risk

Which of the following is the most appropriate way to handle residual risk?

  1. As long as even a little residual risk remains, the risk treatment counts as a failure, and it must be redone until nothing remains at all.
  2. Residual risk should be handled case by case, at the discretion of the frontline staff member involved, deliberately without keeping any record of the judgment.
  3. Because carrying out risk treatment always brings residual risk to zero, there is no need to review and approve the content again once treatment is finished.
  4. It is the risk that remains after risk treatment has been carried out, and someone in a position of responsibility, such as management, judges and approves whether to accept it.
AnswerD. It is the risk that remains after risk treatment has been carried out, and someone in a position of responsibility, such as management, judges and approves whether to accept it.

No amount of treatment can eliminate risk entirely, and the responsible manager approves whether to accept the amount that remains, judged against the acceptance criteria. The premise that it reaches zero is wrong, and letting the frontline staff decide alone or omitting a record fails to meet accountability. The mere existence of residual risk does not mean the treatment failed.

Q22 | 27001 versus 27002

Which of the following most appropriately describes the relationship between JIS Q 27001 and JIS Q 27002?

  1. Both are standards that define only terminology, with no requirements in scope.
  2. 27001 is a code of practice for implementing controls, and 27002 is the standard that defines the requirements for an ISMS.
  3. Both are standards that define ISMS requirements, and their content is identical.
  4. 27001 is the certification standard that defines the requirements for an ISMS, and 27002 is a code of practice for implementing controls.
AnswerD. 27001 is the certification standard that defines the requirements for an ISMS, and 27002 is a code of practice for implementing controls.

The standard used as the basis for certification is JIS Q 27001, which defines the requirements, while JIS Q 27002 is a code of practice showing how to implement individual controls. The explanation that swaps the two is wrong. Terminology and an overview are defined in JIS Q 27000, and 27001 and 27002 are not identical in content.

Q23 | What gets certified

A company announced, “We have obtained JIS Q 27002 certification.” Which of the following is the most appropriate problem with this statement?

  1. 27002 is a code of practice for implementing controls, not a certification standard; ISMS certification is granted against JIS Q 27001.
  2. 27002 is a standard that shows terminology and an overview, and does not cover concrete controls.
  3. 27002 is a standard that covers only the protection of personal information, so it cannot be used for certifying a general company that deals with information security as a whole.
  4. 27002 is a certifiable standard, but only government agencies and independent administrative agencies can obtain it; private companies are outside its scope.
AnswerA. 27002 is a code of practice for implementing controls, not a certification standard; ISMS certification is granted against JIS Q 27001.

The examination criterion under the ISMS conformity assessment scheme is JIS Q 27001, which defines the requirements; 27002 cannot serve as a certification standard. 27002 is a guide to controls, not a terminology standard (27000) or a personal-information-protection standard (15001), and there is no such restriction on which types of organizations can obtain certification.

Q24 | The statement of applicability

Which of the following is the most appropriate content to record in an ISMS statement of applicability?

  1. The controls that were selected, the reasons for selecting them, their implementation status, and the reasons for excluding any controls not adopted
  2. A list of failures that occurred over the past year and a record summarizing the time taken to recover from each
  3. Draft apology letters to send to customers when an incident occurs, and a list of the contacts they should be sent to
  4. The results of each employee's personnel evaluation and a table listing the work goals they set for the coming year
AnswerA. The controls that were selected, the reasons for selecting them, their implementation status, and the reasons for excluding any controls not adopted

A statement of applicability is a document that explains which controls were chosen and why, how far they have been implemented, and, for any controls not adopted, the reason for excluding them. Draft apologies, failure records, and personnel evaluations are all separate documents and do not serve the role of justifying which controls were chosen or excluded.

Q25 | PDCA

In the ISMS PDCA cycle, at which stage are internal audit and management review positioned?

  1. Do
  2. Check
  3. Plan
  4. Act
AnswerB. Check

Internal audit and management review are activities that confirm whether operations are being carried out as decided and functioning effectively, so they belong to Check. Plan covers deciding the scope, formulating policy, risk assessment, and selecting controls; Do covers introducing and operating the controls; and Act covers corrective action and reviewing the system.

Q26 | Internal audit

Which of the following is the most appropriate point to keep in mind when carrying out an ISMS internal audit?

  1. Treat internal audit as something only an outside certification body performs, and assume the organization itself never carries it out.
  2. When a nonconformity is found during an internal audit, simply give a verbal warning without keeping any record.
  3. Choose auditors who are independent of the work being audited, so that objectivity and fairness can be maintained.
  4. To keep the audit objective, the auditor audits and evaluates the work they themselves are in charge of.
AnswerC. Choose auditors who are independent of the work being audited, so that objectivity and fairness can be maintained.

Auditing one's own work tends to produce a lenient evaluation, so auditors should be chosen from people independent of the work being audited. An internal audit is an activity the organization itself carries out; what a certification body performs is a third-party examination. A nonconformity must be recorded and lead to corrective action.

Q27 | The Privacy Mark

When the Privacy Mark is granted, which standard is examined for conformity?

  1. ISO/IEC 27017
  2. JIS Q 27001
  3. JIS Q 15001
  4. JIS Q 27002
AnswerC. JIS Q 15001

The Privacy Mark is granted after examining conformity with JIS Q 15001, which defines the requirements for a personal information protection management system (PMS). JIS Q 27001 is the standard for ISMS certification, 27002 is a code of practice for controls, and ISO/IEC 27017 is a code of practice for cloud service controls.

Q28 | Related standards

Which combination correctly describes ISO/IEC 27017 and ISO/IEC 27701?

  1. 27017 is a code of practice for information security controls for cloud services, and 27701 is a standard for a privacy information management system.
  2. 27017 covers occupational health and safety, and 27701 covers business continuity management requirements.
  3. 27017 is a standard covering the security of control systems used in factories and similar settings, and 27701 defines standard cryptographic algorithms and key lengths.
  4. 27017 is a standard for a quality management system and 27701 is a standard for an environmental management system, neither related to information security.
AnswerA. 27017 is a code of practice for information security controls for cloud services, and 27701 is a standard for a privacy information management system.

ISO/IEC 27017 is a guide to information security controls aimed at both cloud service providers and users, and ISO/IEC 27701 extends an ISMS into a PIMS covering the handling of personal information. Quality, environmental, occupational health and safety, and business continuity are each entirely separate families of standards, so none of the other descriptions applies.

Q29 | The conformity assessment scheme

Which of the following most appropriately describes the ISMS conformity assessment scheme?

  1. A scheme in which an organization self-inspects its own ISMS and is treated as certified simply by declaring on its own that it conforms to the requirements.
  2. A scheme in which a third-party certification body examines whether an organization's ISMS conforms to the requirements of JIS Q 27001, and grants certification.
  3. A scheme in which a public body collectively inspects the vulnerabilities of the information systems an organization uses and, if no problems are found, publicly guarantees their safety.
  4. A scheme in which, once certification is obtained, it remains valid indefinitely without any further examination.
AnswerB. A scheme in which a third-party certification body examines whether an organization's ISMS conforms to the requirements of JIS Q 27001, and grants certification.

The conformity assessment scheme centers on examination and certification by a third party, not a self-declaration. Its subject is the management system, not a vulnerability inspection of individual systems, and even after certification is obtained, an organization must continue to undergo periodic surveillance audits and a renewal audit every few years.

Q30 | Three tiers

When an information security policy is organized into three tiers, which of the following correctly orders them from top to bottom?

  1. Standards → basic policy → procedures
  2. Procedures → standards → basic policy
  3. Basic policy → procedures → standards
  4. Basic policy → standards → procedures
AnswerD. Basic policy → standards → procedures

At the top is the basic policy, which states the organization's stance; below it are standards, which set out what must be observed in each area; and at the bottom are procedures, which show the concrete way of doing things. The higher the tier, the more abstract and stable it is, and the lower the tier, the more concrete and frequently revised. No other ordering matches the role of each tier.

Q31 | The basic policy

Which of the following is the most appropriate content for the basic policy of an information security policy?

  1. The asset numbers of the PCs used by each department along with their locations and users
  2. The product name of the antivirus software and the concrete steps for updating its definition files on screen
  3. The firewall rules configured on each server and a list of the port numbers allowed
  4. The purpose of the organization's information security efforts, its scope of application, and management's responsibility and obligation to comply
AnswerD. The purpose of the organization's information security efforts, its scope of application, and management's responsibility and obligation to comply

The basic policy should state the organization's stance — its purpose, scope, management's responsibility and commitment, and the obligation to comply. Concrete matters such as a product name, operating steps, or port numbers belong in procedures, and asset numbers or locations belong in the information asset inventory; these belong to a different tier.

Q32 | Which tier

Where does a rule such as “A password used for business must be at least 12 characters long and include uppercase letters, lowercase letters, numbers, and symbols” belong among the three tiers of an information security policy?

  1. Procedures
  2. Standards
  3. Basic policy
  4. Statement of applicability
AnswerB. Standards

Standards define what must be observed in each area at the level of “what to do.” The basic policy states the organization's stance and does not include individual requirements, and procedures go as far as documenting how to operate a settings screen. A statement of applicability is a document showing the controls selected under an ISMS, not a tier of the policy.

Q33 | Procedures

Which of the following is the most appropriate characteristic of the procedures tier of an information security policy?

  1. Because it is a document showing the organization's stance, it is written concisely on the assumption it will be published externally, and concrete configuration values are left out.
  2. Once established, it is a document whose content must never be changed, even if the system is replaced.
  3. It is a document referenced only by management, never distributed to frontline staff, and its content is kept confidential even during operation.
  4. It shows concrete operating steps and configuration values, who is responsible, and how records are kept, and it is revised frequently as systems change.
AnswerD. It shows concrete operating steps and configuration values, who is responsible, and how records are kept, and it is revised frequently as systems change.

Procedures form the manual layer that shows “how to do it,” and precisely because they are concrete, they are revised frequently. It is the basic policy that is meant for external publication, and procedures are documents used by frontline staff. If procedures are not updated to match system changes, they stop matching reality.

Q34 | CISO

Which of the following is the most appropriate role of a CISO?

  1. Serving as the contact point for customer inquiries, guiding them on how to use the company's products or configure them.
  2. Handling tasks such as setting up PCs in each department or wiring the network.
  3. Overseeing the organization's information security strategy and measures as a whole, and reporting to management.
  4. Examining the organization's ISMS from a third-party standpoint and objectively deciding whether certification should be granted.
AnswerC. Overseeing the organization's information security strategy and measures as a whole, and reporting to management.

A CISO (chief information security officer) oversees information security across the entire organization and reports the situation to management. Handling customer inquiries or setting up equipment is the job of the relevant department, and a third-party examination is the role of a certification body; neither is the CISO's role.

Q35 | Approving an exception

Due to a business partner's requirement, it became necessary to use a file-sharing service that internal regulations prohibit using. Which response is most appropriate for the staff member involved?

  1. Apply for an exception, stating the reason for use, the data involved, the period, and an alternative control, and use the service only after getting the responsible manager's approval and having it recorded.
  2. Say nothing to the business partner, and end up exchanging work data through a personal cloud account outside the company's control
  3. Interpret the situation as one the internal regulations do not cover, and start using the service right away based on personal judgment, prioritizing getting the work done first
  4. Treat the business partner's instruction as taking precedence over internal regulations, start using it without any approval or record from the responsible manager, and give only a brief verbal report afterward
AnswerA. Apply for an exception, stating the reason for use, the data involved, the period, and an alternative control, and use the service only after getting the responsible manager's approval and having it recorded.

When circumstances make it impossible to follow the regulations as written, the exception-approval process should be used to spell out the reason, the period, and an alternative control, get the responsible manager's approval, keep a record, and review it once the period ends. Acting on one's own judgment, using a business partner's instruction as an excuse to skip approval, or using a personal account all end up putting information outside the organization's control.

Q36 | The cybersecurity management guidelines

Which of the following most appropriately describes the Cybersecurity Management Guidelines?

  1. A technical document aimed at information system engineers, laying out detailed configuration values and work procedures for firewalls and servers.
  2. A set of guidance for management, presenting three principles executives should be aware of and ten important items executives should direct their CISO and others to carry out.
  3. A law that defines the obligations businesses handling personal information must comply with and the legal penalties for violating them.
  4. An international standard that defines the requirements an organization seeking ISMS certification must satisfy, used as the criterion for third-party examination.
AnswerB. A set of guidance for management, presenting three principles executives should be aware of and ten important items executives should direct their CISO and others to carry out.

The Cybersecurity Management Guidelines are guidance for management published by the Ministry of Economy, Trade and Industry and IPA, consisting of three principles and ten important items. They are not a technical document defining configuration values, not a law defining penalties, and not a certification standard for examination (that would be JIS Q 27001).

Q37 | Operating the regulations

Which of the following is the most appropriate practice for communicating and reviewing information-security-related regulations?

  1. Communicate them to the relevant people through onboarding training and periodic sessions tailored to the audience, and review them whenever a law is revised, new technology is introduced, the organization changes, an incident occurs, or an audit raises a finding.
  2. When a violation occurs, treat it uniformly as the individual employee's own responsibility even if the regulation was never communicated to them, and skip reviewing the regulation.
  3. Once regulations are established, keep them unchanged even when a law is revised or the organization changes.
  4. It is enough to place the regulations on an internal server where anyone can view them; there is no particular need to communicate them again through onboarding training or periodic sessions.
AnswerA. Communicate them to the relevant people through onboarding training and periodic sessions tailored to the audience, and review them whenever a law is revised, new technology is introduced, the organization changes, an incident occurs, or an audit raises a finding.

Regulations only function once they have been communicated, and they need to be reviewed as circumstances change. Simply placing them somewhere does not mean they are read, and banning revisions leaves them out of step with reality. Unilaterally blaming an employee for violating a regulation that was never communicated to them is not an appropriate practice.

Q38 | BCP versus BCM

Which of the following most appropriately describes the relationship between a BCP and BCM?

  1. A BCP is a document compiled for management to read, and BCM is a document compiled for frontline staff to read — a distinction based purely on the intended reader.
  2. BCP and BCM mean the same thing; the two terms are synonyms.
  3. A BCP is the plan itself, setting out how critical operations will be continued and recovered, and BCM is the overall management activity of formulating that plan and continuing to train, drill, review, and revise it.
  4. BCP refers to the entire set of day-to-day information security operations, and BCM refers only to the technical measures within it, such as device configuration and monitoring.
AnswerC. A BCP is the plan itself, setting out how critical operations will be continued and recovered, and BCM is the overall management activity of formulating that plan and continuing to train, drill, review, and revise it.

A BCP is the deliverable, a plan, while BCM is the management activity of creating that BCP and continuing to train on it, drill it, review it, and improve it. Neither term refers to day-to-day security operations or technical measures, and the distinction is not about who the intended reader is, nor are the two synonyms.

Q39 | RTO and RPO

Which combination correctly describes RTO and RPO?

  1. RTO is the target for which point in time to restore data back to, and RPO is the target for how much time may be spent from the failure until recovery.
  2. Both RTO and RPO represent the target level to which operations should be restored after recovery, and there is no difference between them.
  3. RTO represents the number of backup generations retained, and RPO represents the type of storage medium used for backups.
  4. RTO is the target for how much time may be spent from the failure until recovery, and RPO is the target for which point in time to restore data back to.
AnswerD. RTO is the target for how much time may be spent from the failure until recovery, and RPO is the target for which point in time to restore data back to.

RTO (recovery time objective) is a target for time, and RPO (recovery point objective) is a target for data freshness, that is, the acceptable range of data loss. The explanation that swaps the two is wrong. The target that represents the level of operational recovery is RLO, and neither the number of backup generations nor the type of medium represents either of these metrics.

Q40 | RPO and interval

A system has set its RPO at 4 hours. Which of the following operating practices is most appropriate for meeting this target?

  1. Establish a system and procedures capable of restoring the system within 4 hours of a failure occurring, and also carry out regular recovery drills.
  2. Take backups at least every 4 hours, so that no more than the most recent 4 hours of data is lost in the event of a failure.
  3. Set a target of restoring the system's processing capacity, once recovered, to at least a quarter of its normal level, and build a system around that.
  4. Prepare four different types of backup media, and switch to storing each of them in a separate location.
AnswerB. Take backups at least every 4 hours, so that no more than the most recent 4 hours of data is lost in the event of a failure.

Because RPO represents the acceptable range of data loss, a 4-hour RPO requires the backup interval to be kept to 4 hours or less. Restoring within 4 hours is a matter for RTO, and the level of recovery is a matter for RLO; preparing four types of media has nothing to do with RPO.

Q41 | RLO

A business continuity plan states, “After a disaster occurs, first resume only order-taking operations, at 50% of normal processing capacity.” Which metric represents this target?

  1. BIA (business impact analysis)
  2. RPO (recovery point objective)
  3. RLO (recovery level objective)
  4. RTO (recovery time objective)
AnswerC. RLO (recovery level objective)

RLO is the metric that shows the level to which operations should be restored once recovery has occurred. RTO is the metric for the time until recovery, and RPO is the metric for which point in time data should be restored to; BIA is an analysis activity that clarifies which operations should be recovered first, not a metric.

Q42 | BIA

Which of the following is the most appropriate purpose of a business impact analysis (BIA)?

  1. Measuring each employee's workload and working hours to optimize staffing by department.
  2. Comprehensively inspecting the vulnerabilities present in an information system to identify what needs fixing and its priority, and drawing up a remediation plan in advance.
  3. Analyzing the size and time-based spread of the impact if operations were to stop, to identify which critical operations should be recovered first and what resources they depend on.
  4. Comparing the unit prices of backup media and selecting the cheapest one to cut costs.
AnswerC. Analyzing the size and time-based spread of the impact if operations were to stop, to identify which critical operations should be recovered first and what resources they depend on.

A BIA analyzes which operations, if halted, cause how much damage and by when, and identifies the priority order for recovery and the resources each operation depends on, forming the basis for drawing up a BCP. Optimizing staffing, inspecting vulnerabilities, and comparing media prices are none of them the purpose of a BIA.

Q43 | Restoring from incrementals

A full backup is taken on Sunday, and an incremental backup is taken every day from Monday through Saturday. If a failure occurs on Thursday night, which combination of backups is needed to restore the system?

  1. Just two: the full backup taken on Sunday and the incremental backup taken on Thursday
  2. All of the incremental backups from Monday through Thursday, excluding Sunday's full backup
  3. Sunday's full backup and all of the incremental backups from Monday, Tuesday, Wednesday, and Thursday
  4. Only the incremental backup taken on Thursday, the one immediately before the failure, with none of the earlier ones
AnswerC. Sunday's full backup and all of the incremental backups from Monday, Tuesday, Wednesday, and Thursday

Because an incremental backup holds only the changes made since the previous backup, restoring requires the full backup plus every incremental taken since then. Missing even one makes restoration impossible. Being able to restore with just the full backup and the single most recent one is the case for differential backups.

Q44 | Restoring from differentials

A full backup is taken on Sunday, and a differential backup is taken every day from Monday through Saturday. If a failure occurs on Thursday night, which combination of backups is needed to restore the system?

  1. Only Thursday's differential backup
  2. All of the differential backups from Monday through Thursday
  3. Sunday's full backup and Thursday's differential backup
  4. Sunday's full backup and all of the differential backups from Monday, Tuesday, Wednesday, and Thursday
AnswerC. Sunday's full backup and Thursday's differential backup

A differential backup holds all changes made since the last full backup each time it is taken, so the most recent differential already includes every change up to that point. Restoration therefore only needs two backups: the full one and the latest differential. Needing every differential is the case for incremental backups.

Q45 | 3-2-1

Which of the following most appropriately describes the 3-2-1 backup rule and how it should be applied to storage as a countermeasure against ransomware?

  1. It is a guideline for a procedure in which three staff members double-check something and one responsible person approves it before a backup is taken.
  2. It is a guideline for how often to take backups and how long to keep them: take backups three times a day, retain two weeks' worth, and discard anything older than a year.
  3. Keep three copies of the data, including the original, on two different types of media, with one of them stored in a separate location; in addition, disconnect a backup from the network and store it offline once it has been taken.
  4. It is a storage scheme that double-encrypts data with three different cryptographic algorithms and centrally manages the keys in one location.
AnswerC. Keep three copies of the data, including the original, on two different types of media, with one of them stored in a separate location; in addition, disconnect a backup from the network and store it offline once it has been taken.

The 3-2-1 rule is a storage guideline: three copies of the data, two types of media, and one copy kept in a separate location. Because ransomware can also encrypt networked shared folders and NAS devices, an always-connected backup alone cannot protect against it, which is why offline storage is effective. The other choices concern the frequency of backups, an approval procedure, or an encryption scheme, none of which relates to this rule.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original