Karinoya Learning Room

Qualifications · Information Security Management (SG) Success Lab

Information Asset and Risk Practices

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Where to start the inventory

Company A is an industrial-equipment sales company with 120 employees. B, in the sales department, has been appointed the department's information security leader and is creating the sales department's information asset inventory for the first time. The sales department has contact information for customer representatives registered in the customer management system, paper contracts, business cards collected at trade shows, quotation files in Excel, loaned laptops, and a cloud service for sales support. When B consulted the information systems department, they were told, “We know what's on the servers, but we don't know about information the department holds on its own.” What should B do first in creating the inventory?

  1. Report to the information security committee that the inventory has not been made, and wait for company-wide instructions before doing anything
  2. Transcribe the list of servers managed by the information systems department directly as the sales department's inventory
  3. Decide confidentiality, integrity, and availability ratings only for the data held in the customer management system
  4. Identify everything the sales department handles in its work, without distinguishing electronic data, paper, equipment, or outside services
AnswerD. Identify everything the sales department handles in its work, without distinguishing electronic data, paper, equipment, or outside services

Building an inventory starts with identifying what is in scope. Information assets are not limited to electronic data; they also include paper, equipment, and outside services, so the first task is to list what is handled in the work regardless of medium. Deciding rating values comes after identification, and narrowing the scope up front leaves gaps. Transcribing the server list would miss the department's own paper documents, business cards, and cloud service. Waiting for the committee's instructions is not a reason to stop gathering what the department already knows it holds.

Q2 | What the inventory records

B in Company A's sales department identified the department's information and created the first version of the information asset inventory. The sales department handles customer contact information registered in the sales management server, original contracts kept in the third-floor archive, business cards collected at trade shows and visits, and a quotation template placed in a shared folder. B filled in the columns for using department, responsible manager, storage location, medium, and record count for each asset. For business cards, having heard that “each staff member receives and keeps their own,” B recorded it as such. Before submitting the finished inventory to a supervisor, B is checking whether there is any problem with how it was recorded. Which entry in this inventory most needs to be revised?

A社営業部 情報資産台帳(初版・抜粋)
No  資産名          利用部門  管理責任者    保管場所          媒体  件数1   顧客連絡先一覧  営業部    営業部長      販売管理サーバ    電子  8,4002   契約書原本      営業部    営業事務課長  3階書庫(施錠)     紙    1,2003   受領した名刺    営業部    営業部全員    各自の名刺入れ    紙    不明4   見積書ひな形    営業部    営業企画課長  部門共有フォルダ  電子  40
  1. No. 4 — An asset that is never taken outside the company does not need to be recorded in the inventory
  2. No. 1 — An asset with a large record count must always be split across multiple rows, one per count
  3. No. 3 — The responsible manager is not identified as a specific individual, and neither the storage location nor the record count is tracked
  4. No. 2 — Paper documents are outside the scope of an information asset inventory, so this row should be deleted from it
AnswerC. No. 3 — The responsible manager is not identified as a specific individual, and neither the storage location nor the record count is tracked

The responsible-manager column exists to show where judgment and responsibility lie, so it should name a single individual down to their title and name. “Everyone in the sales department” leaves it undecided who actually judges, and a storage location of “each person's own business card holder” with a record count of “unknown” likewise shows that management is not reaching it. A large record count is not a reason to split rows, and paper documents are included among information assets. Whether something is taken outside the company has nothing to do with whether it needs to be recorded in the inventory.

Q3 | An asset spanning departments

At Company A, customer information entered by the sales department when taking an order is used by the logistics department to confirm the delivery address and by the accounting department to issue invoices. The customer information is stored in a sales management system operated by the information systems department. In creating the information asset inventory, the departments disagree over who should be the responsible manager for this customer information. Logistics and accounting each claim they “merely use it,” while the information systems department says it “merely holds the server and doesn't know the content.” Which is the most appropriate way to decide the responsible manager?

  1. Make the head of the information systems department, which operates the system storing the information, the responsible manager, and list sales, logistics, and accounting alongside it in the inventory as using departments
  2. Make the manager of the sales department, which generates the information in the course of its work and bears responsibility for its content and scope of use, the responsible manager, and list logistics and accounting alongside it in the inventory as using departments
  3. Register the managers of all three using departments jointly as the responsible manager, deciding by consensus
  4. Do not designate a responsible manager, and record only the using departments in the inventory
AnswerB. Make the manager of the sales department, which generates the information in the course of its work and bears responsibility for its content and scope of use, the responsible manager, and list logistics and accounting alongside it in the inventory as using departments

For information that spans departments, the principle is to make the manager of the business department that generates the information in the course of its work, and bears responsibility for the correctness of its content and the scope in which it is used, the responsible manager. The information systems department is in the position of operating the system and does not bear responsibility for the content itself. A joint designation leaves no one who makes the final call, and leaving it blank erases where responsibility lies at all. The using departments should be listed in a separate column so the scope of impact is clear.

Q4 | Updating the inventory

Company A has decided to update its information asset inventory during an annual inventory-taking exercise every March. This fiscal year in the sales department, the person in charge of the customer management system changed hands in an April personnel transfer. In June, a new sales-support cloud service was introduced and began storing negotiation history. In September, 1,000 paper contracts were moved from the internal archive to an outside warehouse. In November, one contract employee left, and another staff member took over the quotation files that person had handled. B thinks, “The annual inventory-taking is in March, so the inventory can stay as it is until then.” Which of the following is the most appropriate criticism of this thinking?

  1. Information stored on a cloud service is something the provider manages, so it does not need to be listed in the company's own inventory
  2. The inventory only needs to be updated when a system is replaced; a personnel transfer or a change of storage location falls outside the scope of an update
  3. The inventory should be updated as soon as an asset changes, and the annual inventory-taking should be positioned as the occasion for filling in any overall gaps
  4. The inventory is a record as of the time it was created, so once finalized it should never be changed at all, and a new one should be made from scratch the following fiscal year
AnswerC. The inventory should be updated as soon as an asset changes, and the annual inventory-taking should be positioned as the occasion for filling in any overall gaps

An inventory is only useful once it matches reality. Relying solely on the annual inventory-taking leaves it out of step by up to a year, so the basic practice is to update it as soon as a change happens — the start of a new service, a change of the person in charge, a change of storage location, a handover following a departure — with the annual exercise there to catch anything missed. Limiting updates to system replacements, or never changing it once finalized, only locks in the drift. Information held on a cloud service is still an information asset the company is responsible for and belongs in the inventory.

Q5 | Gaps in the survey

B in Company A's sales department identified information assets through an internal survey. The responses gathered covered only three things: data in the customer management system, proposals in a shared folder, and contracts in the archive. But walking around the department in person, B found a staff member keeping a customer-list Excel file on their loaned laptop's desktop, a staff member saving proposals to a personally contracted free cloud storage service and editing them from home, a staff member keeping a bundle of business cards collected at trade shows in a drawer, and a staff member holding onto a USB drive taken over from a colleague who had left the company. None of these appeared in the survey responses. Which of the following is the most appropriate response for B?

  1. Since business cards and a USB drive are small in quantity, register them together as a single entry called “other” without counting them
  2. Add the information found through the on-site check to the inventory as well, and revise the identification method so it does not rely on self-reporting alone
  3. Consider the identification work complete once a new regulation banning use of free cloud storage has been drawn up
  4. Put only the assets written in the survey into the inventory, and treat everything else as personal belongings managed by the individual
AnswerB. Add the information found through the on-site check to the inventory as well, and revise the identification method so it does not rely on self-reporting alone

Files on a personal PC, an unapproved cloud service, a handed-down portable medium, and paper in a drawer are all classic gaps that self-reporting fails to surface. They need to be picked up through a combination of on-site checks and reviewing actual usage, and reflected in the inventory. Treating them as personal belongings puts company information outside the company's management. Drawing up a regulation is necessary but is separate from completing the identification, and lumping them together without counting them hides the actual state of management.

Q6 | The state of management

B in Company A's sales department created the department's information asset inventory and has been asked to check for any asset that is not being properly managed. A supervisor said, “There's no time to check everything at once, so please look at the risky ones first.” The inventory records, for each asset, the medium, storage location, record count, and whether it may be taken out. B thinks the state of management can be read from the entries themselves and is comparing rows. An excerpt of the inventory is shown below. Which asset should be given top priority for an on-site check?

A社営業部 情報資産台帳(抜粋)
No  資産名          媒体  保管場所                    件数   持出し1   顧客連絡先一覧  電子  社内ファイルサーバ          8,400  不可2   契約書原本      紙    3階書庫(施錠)               1,200  不可3   商談メモ        電子  各自の貸与PCのデスクトップ  不明   可4   請求書控え      紙    営業部キャビネット(施錠)    3,000  不可
  1. No. 1 (customer contact list)
  2. No. 3 (negotiation notes)
  3. No. 4 (invoice copies)
  4. No. 2 (original contracts)
AnswerB. No. 3 (negotiation notes)

No. 3 has its storage location scattered across each staff member's own PC, an unknown record count, and permission to take it out, showing a state where the organization does not know how many copies exist or where. No. 1, No. 2, and No. 4 each have a storage location fixed to one place, a known record count, and restricted removal, showing that management is reaching them as recorded in the inventory. A record count of “unknown” is a classic sign that management has not reached an asset, making it the one to check on site first.

Q7 | Handover upon departure

Team lead C in Company A's sales department is due to leave at the end of next month. C has stored the negotiation history for 20 client companies in a local folder on a loaned laptop and in a business email inbox, with only some of it placed in the department's shared folder. C also keeps a USB drive containing drawings entrusted by a client in a desk drawer. Told by a supervisor to “finish the handover before the departure,” B, as information security leader, needs to organize the procedure. What should B do first?

  1. Reinitialize the laptop C used on the last working day, and discard the loaned USB drive without checking its contents
  2. Identify and list the information C holds in the course of the job, and confirm with the responsible manager which of it should be handed over as an information asset
  3. Have the supervisor read through all of C's business email inbox and forward whichever messages seem necessary to the department's shared folder one by one
  4. Immediately disable every internal account loaned to C, so that C cannot use any internal system at all until the last working day
AnswerB. Identify and list the information C holds in the course of the job, and confirm with the responsible manager which of it should be handed over as an information asset

Information held by someone who is leaving tends to fall out of the inventory, so the starting point is first identifying and listing what that person holds and confirming with the responsible manager which of it should be handed over as an information asset. Reinitializing or discarding items without this confirmation would lose even necessary information, such as drawings entrusted by a client. Disabling all accounts immediately while the person is still employed halts both work and the handover. Starting with the inbox does not amount to identifying the full scope and is not the right order.

Q8 | An unapproved service

In Company A's sales department, a staff member had, for the sake of efficiency, signed up for an online survey service on a free plan. This service was used to collect the names, company names, and email addresses of trade-show visitors, later used for sales activity. No usage application had been filed with the information systems department, and only a few people in the department even knew it existed. When B found this in the course of identifying information assets, about 600 records had already been collected. The service's admin screen was set up so two staff members could log in with personal accounts. Which of the following is the most appropriate response for B?

  1. Since the free plan incurs no cost, do not register it in the inventory and let its use continue as-is
  2. List the two account holders' names in the responsible-manager column and leave all further management to those two
  3. Immediately delete all collected personal information and cancel the service, skipping both an internal report and a record in the inventory
  4. Record the information being collected and its usage in the inventory, go through the internal application process, and check the provider's security control measures
AnswerD. Record the information being collected and its usage in the inventory, go through the internal application process, and check the provider's security control measures

Even a cloud service used without approval (shadow IT) is an information asset the company is responsible for if personal information is stored on it. The right path is to first record the actual state in the inventory to make it visible, put it through the internal application process, and check the provider's security control measures. Whether it costs money is not the criterion for whether to register it in the inventory. Deleting and canceling it without authorization while skipping a report amounts to hiding the facts. Leaving everything to the two account holders abandons the organization's own management responsibility.

Q9 | The scope of assets

Starting this fiscal year, Company A has decided to build an information asset inventory in every department, and general affairs held a briefing session. After the session, several staff members asked B in the sales department, “How far does the inventory go in counting something as an information asset?” The sales department has a customer database, paper contracts, loaned laptops and smartphones, quotation software, and an outside sales-support cloud service. There is also negotiation and discount know-how known only to veteran employees. One staff member argued, “equipment listed in the company's equipment inventory shouldn't count as an information asset,” while another said, “data on the cloud belongs to the provider.” Which explanation of the scope of information assets is most appropriate?

  1. Only things whose monetary value can be estimated count as information assets; things that cannot be estimated, like the know-how a person holds, are outside the scope
  2. Electronic data, paper documents, equipment, software, outside services, and knowledge held by people are all treated as information assets as long as they have value to the business
  3. Only things the company owns and keeps in-house are information assets; information stored on an outside cloud service and knowledge held by people are not included
  4. Only electronic data is an information asset; paper documents, equipment, and outside services are not included
AnswerB. Electronic data, paper documents, equipment, software, outside services, and knowledge held by people are all treated as information assets as long as they have value to the business

An information asset is not determined by its medium or form of ownership; it is judged by whether it has business value and whether there is a responsibility to protect it. This includes not only electronic data but paper documents, hardware, software, outside services, and even know-how held by people. Excluding paper or equipment, or excluding information on an outside service, puts information that genuinely needs protection outside the scope of management. Information whose monetary value cannot be estimated still needs protection if the impact of a leak or an outage would be large.

Q10 | Deciding importance

Company A has a company-wide unified rule for deciding an information asset's importance. Confidentiality, integrity, and availability are each rated on a three-level scale of high (3), medium (2), or low (1), and the rule states that an asset's importance equals the highest of its three ratings. B in the sales department rated the department's main assets under this rule and got the results below. B wants to pull out the assets rated “high” in importance to prioritize countermeasures for them. Under this rule, which combination of assets is rated “high” in importance?

A社営業部 情報資産の評価結果(高=3・中=2・低=1)
No  資産名          機密性  完全性  可用性1   顧客連絡先一覧  高      中      中2   見積書ひな形    低      中      低3   受注データ      中      高      高4   展示会案内文    低      低      低
  1. No. 2 and No. 3
  2. No. 3 and No. 4
  3. No. 1 and No. 2
  4. No. 1 and No. 3
AnswerD. No. 1 and No. 3

Under the maximum-value method, importance equals the highest of the three ratings. No. 1's highest is confidentiality at high, so its importance is high; No. 3's highest is integrity and availability at high, so its importance is high too. No. 2's highest is integrity at medium, giving importance medium, and No. 4 is low across the board, giving importance low. So No. 1 and No. 3 are rated high. The key point is judging by the maximum value, not an average or a sum.

Q11 | What to evaluate

To explain the way of thinking behind ratings to the department's staff, B in Company A's sales department used a price sheet listing discount rates by customer as an example. If this price sheet reached a competitor, it would put the company at a disadvantage in price negotiations. If a figure on it were mistakenly rewritten, an incorrect quoted price could be presented to a customer, which would later have to be retracted. On the other hand, if a system failure made it unreadable for about half a day, business could continue using a printed copy from the previous month as a substitute. What is the most appropriate rating for this price sheet?

  1. Confidentiality high, integrity low, availability high
  2. Confidentiality low, integrity low, availability low
  3. Confidentiality low, integrity high, availability high
  4. Confidentiality high, integrity high, availability low
AnswerD. Confidentiality high, integrity high, availability low

Confidentiality is judged by the impact if the information leaked, so it is high given the disadvantage in price negotiations if it reached a competitor. Integrity is judged by the impact if an error occurred, so it is high given that it could lead to presenting an incorrect quoted price. Availability is judged by the impact if it became unusable, so it is low given that a printed copy can substitute for half a day of downtime. If availability is decided by how important or frequently used the information is, the presence of a substitute, the actual thing to consider, gets overlooked.

Q12 | Overrating

In Company A's sales department, information asset ratings were left to each staff member's own judgment, and almost every asset ended up rated “confidentiality high.” Under the company's handling standard, an asset rated high for confidentiality requires storage in a locked archive, a supervisor's approval to take it out, and encryption plus a handover record when shared outside the company. As a result, even taking out a trade-show invitation flyer or an already-published product catalog required approval. Approval requests climbed from a dozen or so a month to nearly two hundred. Eventually the supervisor started stamping approval without checking the content, and it turned out that even taking out the truly sensitive customer list was sailing through unchecked. Which of the following is the most appropriate response for B?

  1. To reduce the burden of approval, abolish the supervisor's approval step for taking items out altogether, regardless of importance, for every asset
  2. Uniformly lower the rating of every asset the sales department holds to “medium,” and greatly simplify the handling standard even for assets with high confidentiality
  3. Present a rating standard that can be judged by the actual size of the impact, redo the ratings, and lower the rating of low-impact assets such as public information to match reality
  4. Leave the asset ratings as they are, and change the approver for taking items out from the supervisor to the very staff member who is actually taking it outside the company, across the board
AnswerC. Present a rating standard that can be judged by the actual size of the impact, redo the ratings, and lower the rating of low-impact assets such as public information to match reality

The root cause of the problem is overrating, rating even public information as high, so the proper fix is to redo the ratings using a standard defined by concrete impact. Abolishing approval entirely or uniformly lowering everything to medium would also weaken protection for information that genuinely needs it. Changing the approver to the person taking the item out themselves removes third-party checking and empties approval of its meaning. Note that overrating hollows out the procedure and, as a result, ends up loosening the management of important information too.

Q13 | Classification and handling

Company A has a handling standard tied to an information asset's importance. B in the sales department has been asked by the sales manager to provide a customer contact list, rated “high” in importance, to an outside agency for a joint campaign with a business partner. A services contract exists with the agency, but B has not checked whether it includes a confidentiality clause. The sales manager has said, “The campaign is starting soon, so please hurry.” An excerpt of the handling standard is shown below. What should B do first?

A社 情報取扱い基準(重要度別・抜粋)
重要度  保管                  持出し        社外共有                廃棄高      施錠書庫または暗号化  上長承認必須  契約と部門長承認が必要  溶解またはデータ消去の記録中      施錠書庫              上長承認必須  上長承認が必要          溶解またはデータ消去低      指定なし              承認不要      承認不要                一般廃棄可
  1. Change the customer contact list's importance to “medium” so it can be provided with just a supervisor's approval
  2. Check whether the contract with the agency contains a confidentiality clause, and proceed with obtaining the department head's approval
  3. Since narrowing the number provided to 100 records would lower the importance, create an excerpted version and provide it without approval
  4. Send it to the agency's contact person as a password-protected compressed file, and communicate the password in a separate message
AnswerC. Since narrowing the number provided to 100 records would lower the importance, create an excerpted version and provide it without approval

Sharing an asset rated high in importance outside the company requires, under the standard, both a contract provision and the department head's approval. So checking the confidentiality clause and proceeding with the department head's approval comes first. Sending it encrypted is merely a method of handover and is no reason to skip a required approval. Lowering the rating to bypass the procedure hollows out the standard, and reducing the record count does not change the nature of the information, so the importance does not go down.

Q14 | Underrating

In Company A's sales department, the sales activity report file was rated “low” in importance on the grounds that it was “just a document shared internally,” and it was placed in a shared folder any staff member could edit. The report sometimes records the name and title of the person visited along with meeting content and trading terms with other companies. One day, a temporary staff member made an operating mistake and copied the report folder into the company-wide shared folder, leaving it viewable by every employee in other departments for two weeks. Following this event, B has to review the rating. Which approach to the review is most appropriate?

  1. Redo the rating based on the impact if the information contained in the report leaked, and apply a handling rule that raises the confidentiality rating when it includes high-impact information such as trading terms
  2. Since the report is updated daily and its content keeps changing, exclude it from rating altogether
  3. Since the cause this time was the temporary staff member's operating mistake, leave the report's rating unchanged and prevent recurrence by deleting that person's account
  4. It is enough to review the company-wide shared folder's access rights so staff in other departments cannot see the report, so leave the report's confidentiality rating as it is
AnswerA. Redo the rating based on the impact if the information contained in the report leaked, and apply a handling rule that raises the confidentiality rating when it includes high-impact information such as trading terms

A rating should be decided by the impact if the contained information leaked, not by a document's name or the convention of how widely it is shared. Uniformly rating a report low even though it contains a business partner's contact information and trading terms is underrating, and raising the rating and applying a corresponding handling rule is the substantive fix. Update frequency is not a reason to exclude something from rating. Disciplining an individual or adjusting access rights alone still leaves the same kind of information being handled under a low rating elsewhere.

Q15 | Reviewing the ratings

Company A has set the confidentiality rating standard as: “information that could trigger a legal reporting obligation or damages claim if it leaked is rated high,” “information already published is rated low,” and “information matching neither is rated medium.” In the sales department, each staff member rated a share of the assets, and B compiled the results. In the process, B suspects the standard may have been applied inconsistently between staff members, particularly diverging on whether the information was collected at an outside event. The sales department's rating results are shown below. Which of these ratings needs to be revised against the standard?

A社営業部 機密性の評価結果(抜粋)
No  資産名                  含まれる情報                                機密性の評価1   顧客連絡先一覧          顧客担当者の氏名・電話番号・メールアドレス  高2   展示会来場者アンケート  来場者の氏名・勤務先・メールアドレス        低3   契約書原本              取引条件・押印済みの署名                    高4   製品カタログ(公開版)    公開済みの製品仕様と価格                    低
  1. No. 1 (the sales department's customer contact list)
  2. No. 4 (product catalog currently published on the web)
  3. No. 3 (original contracts)
  4. No. 2 (trade-show visitor survey)
AnswerD. No. 2 (trade-show visitor survey)

No. 2, the visitor survey, contains unpublished personal information — name, employer, and email address — and could trigger a damages claim if it leaked, so against the standard it should be at least medium, and, as the same kind of information as No. 1, arguably high; rating it low is wrong. No. 1 also contains personal information and its high rating is appropriate; No. 3 contains trading terms and its high rating is appropriate; No. 4 is already-published information and its low rating is appropriate. That the information was collected at a trade show, or that the record count is small, is not a reason to lower the rating.

Q16 | Unifying the rating standard

At Company A, each department had been rating information assets in its own terms: sales used “important / normal / minor,” manufacturing used “A / B / C,” and accounting used “a 5-level scale from 1 to 5.” When a company-wide risk assessment tried to compare across departments, it proved impossible to judge which asset should be prioritized for countermeasures. It also turned out that even the same word, “important,” was applied under different reasoning depending on the department. Which of the following is the most appropriate proposal for B, who serves as secretariat for the information security committee?

  1. Define, company-wide, both the rating levels and the criteria (the impact of a leak, alteration, or loss of use) for placing something into each level, and have every department redo its ratings against the same standard
  2. Have the information systems department carry out the company-wide rating on its own, without involving each department in the rating
  3. Standardize every department's notation onto accounting's finer 5-level scale, while leaving the criteria for which level something falls into to each department's discretion as before
  4. Leave each department's rating notation as it is, and have each department pick its own top three to serve as the company-wide list for countermeasures
AnswerA. Define, company-wide, both the rating levels and the criteria (the impact of a leak, alteration, or loss of use) for placing something into each level, and have every department redo its ratings against the same standard

To set priorities across departments, aligning the notation for the levels is not enough; the criteria for placing something into a given level also need to be defined in common language. If the criteria are left to each department's discretion, the same-looking notation can hide different substance, making comparison impossible. Having each department pick its own top three would put a low-importance asset up for a countermeasure while letting an important one slip through elsewhere. It is the using department that knows the content of the information and its business impact, so a rating done unilaterally by the information systems department cannot reflect reality.

Q17 | Rating availability

In Company A's sales department, order data is entered into the sales management system, and shipping instructions and invoicing are all based on this data. If the system stops, shipments cannot go out that day; a full day's outage pushes roughly 20 million yen of sales into the following month and also causes delivery delays to clients. On the other hand, a shared folder holding past negotiation notes causes no major disruption to daily work even if it is unavailable for a week. The negotiation notes also number more records than the order data. B has to decide the availability rating for both. Which way of thinking is most appropriate?

  1. Availability is a matter for the information systems department, which operates the system, to decide, and the sales department, as the using department, should refrain from involvement in the rating
  2. Since both are information used routinely in internal business, set the same availability rating for both
  3. Revise and set the negotiation notes, which hold more records, to a higher availability rating than the order data
  4. Rate by how much business is halted when something becomes unusable and how long an outage can be tolerated, giving the order data high and the negotiation notes low
AnswerD. Rate by how much business is halted when something becomes unusable and how long an outage can be tolerated, giving the order data high and the negotiation notes low

Availability is rated by how much business is halted when something becomes unusable and how much downtime can be tolerated. The order data is rated high because a one-day outage halts shipments and causes delivery delays, while the negotiation notes are rated low because even a week of downtime causes little disruption. Whether it is stored internally, or how many records there are, is not a basis for judgment. It is the using department that knows which business is halted and by how much when something goes down, so staying out of the rating is not appropriate.

Q18 | Risk identification

In Company A's sales department, the customer contact list is kept on the internal file server, configured so every staff member can access it. Last month, it turned out that a departed employee's account had been left un-deleted. Staff members also reference the same file from outside the office over a VPN on their company-issued laptops. B is beginning a risk assessment for this asset, starting with risk identification. Which of the following is the most appropriate task to carry out as risk identification?

  1. Combine the threats to the customer contact list (unauthorized access, internal fraud, loss, etc.) with the vulnerabilities that could be exploited (a leftover unnecessary account, over-granted privileges, etc.) to identify the events that could occur
  2. Estimate the cost of a countermeasure for each identified risk, carry out whichever ones fit within budget starting with the cheapest, and record their implementation status
  3. Immediately delete the departed employee's remaining account on the customer contact list, narrow every staff member's access rights down to what is needed for their work, and consider the whole sequence of work on this asset finished at that point
  4. Estimate the likelihood and the degree of impact for the customer contact list, multiply them to compute the size of the risk, and compare it against the acceptance criteria
AnswerA. Combine the threats to the customer contact list (unauthorized access, internal fraud, loss, etc.) with the vulnerabilities that could be exploited (a leftover unnecessary account, over-granted privileges, etc.) to identify the events that could occur

Risk identification is the process of combining threats and vulnerabilities against an asset to identify the events that could occur. Estimating the size (likelihood × impact) is risk analysis, and estimating cost or carrying out a countermeasure is risk treatment; these come in a different order. Fixing a vulnerability that catches the eye is a useful action, but stopping there leaves other combinations of threat and vulnerability unaddressed. The full identification should come first, before prioritizing.

Q19 | Judging priority

Company A has defined a method for computing risk level and an acceptance criterion in its regulations. Risk level is the product of “likelihood (high 3, medium 2, low 1) × impact (high 3, medium 2, low 1).” A product of 6 or more is treated as an unacceptable risk to be addressed with priority. B in the sales department analyzed the department's risks using this method and got the results below. A supervisor has said, “I want to narrow it down to one item and move ahead with a countermeasure first.” Under this standard, which risk should be addressed with priority?

A社営業部 リスク分析結果(受容基準:積が6以上は受容できない)
No  リスク                          発生可能性  影響度  積1   顧客連絡先一覧の外部への漏えい  低(1)       高(3)   32   退職者アカウントによる不正閲覧  中(2)       高(3)   63   紙の契約書の紛失                中(2)       中(2)   44   展示会案内文の誤送信            高(3)       低(1)   3
  1. No. 2 (unauthorized viewing via a departed employee's account)
  2. No. 3 (loss of an original paper contract)
  3. No. 4 (misdirected email from an incorrect recipient for a trade-show invitation)
  4. No. 1 (a large-scale external leak of the customer contact list)
AnswerA. No. 2 (unauthorized viewing via a departed employee's account)

Since the acceptance criterion is a product of 6 or more, only No. 2, with a product of 6, is an unacceptable risk. No. 1 has a high impact but a low likelihood, giving a product of 3; No. 4 has a high likelihood but a low impact, also giving 3; No. 3's product is 4; all three fall within the criterion. The key point is not to decide priority by looking at impact or likelihood alone, but to check the risk level against the predetermined criterion.

Q20 | The four categories of treatment

In Company A's sales department, a meeting was held to decide the risk-treatment policy in response to the risk assessment results. The sales manager, B, and a representative from the information systems department attended. The discussion resulted in a different kind of treatment for each of four risks. B needs to classify the decisions by type of risk treatment to report them to the company-wide information security committee. The decisions are shown below. When each treatment is classified as risk avoidance, risk reduction, risk transfer, or risk retention (acceptance), which combination is correct?

A社営業部 リスク対応の決定内容
No  リスク                      決めた対応1   展示会での名刺収集時の紛失  名刺の収集をやめ、来場者情報は取引先経由でのみ受け取る2   ファイルサーバへの不正侵入  アクセス権の見直しと多要素認証の導入を行う3   サイバー攻撃による損害賠償  サイバー保険に加入する4   社内掲示板の記載誤り        影響が小さいため対策は行わず、記録を残して年次で再評価する
  1. 1 = avoidance, 2 = reduction, 3 = transfer, 4 = retention
  2. 1 = transfer, 2 = reduction, 3 = avoidance, 4 = retention
  3. 1 = reduction, 2 = avoidance, 3 = retention, 4 = transfer
  4. 1 = avoidance, 2 = transfer, 3 = reduction, 4 = retention
AnswerA. 1 = avoidance, 2 = reduction, 3 = transfer, 4 = retention

Item 1 stops the activity causing the risk itself (collecting business cards), so it is avoidance. Item 2 adds a control to lower the likelihood, so it is reduction. Item 3 shifts the burden of loss to another party through insurance, so it is transfer. Item 4 accepts it as within the criteria with a record kept, so it is retention (acceptance). It also helps to remember that retention is not “doing nothing” — it is a decision that records the reasoning and gets reviewed periodically.

Q21 | Residual risk

In Company A's sales department, a reduction measure such as reviewing access rights was carried out for the risk of a customer contact list leak, but the risk level remained just slightly above the acceptance criterion. Introducing a dedicated data-removal management system is being considered as an additional measure, but it would cost 8 million yen a year. On the other hand, the expected loss from this risk is estimated at around 1 million yen a year. B is working out how to handle the remaining risk. Which response is most appropriate?

  1. Since it exceeds the acceptance criterion, an additional countermeasure must always be carried out regardless of cost
  2. Change the method for computing the risk level and redo the evaluation so that it falls within the acceptance criterion
  3. Organize the cost-effectiveness and the nature of the remaining risk, explain it to the management-level people who bear responsibility, and record it as a residual risk once their approval is obtained
  4. Since the cost is not worth it, B, as information security leader, decides on their own to accept the risk, keeping no particular record
AnswerC. Organize the cost-effectiveness and the nature of the remaining risk, explain it to the management-level people who bear responsibility, and record it as a residual risk once their approval is obtained

When accepting a residual risk that exceeds the acceptance criterion, the cost-effectiveness and the nature of the remaining risk must be presented to the responsible management-level people (executives) to obtain their approval, and this must be recorded. Accepting it on a staff member's or a leader's own authority, with no record kept, lacks an organizational decision. Unconditionally carrying out a countermeasure whose cost greatly exceeds the loss amount is not rational. Changing the calculation method to fit the criterion is making the risk look smaller than it actually is and is not permissible.

Q22 | Reassessment

Company A carries out a risk assessment every April. This fiscal year, a new sales-support cloud service was introduced in June and began storing customer information. In September, a revision to the law governing the handling of personal information took effect. In November, a malware infection incident occurred in another department, and a company-wide alert was issued. In January, the sales department and the sales planning department were merged, changing the responsible manager and the scope of authority. B thinks, “The next assessment is in April, so the current results can stand until then.” Which of the following is the most appropriate criticism of this thinking?

  1. Introducing a new service, a legal revision, an incident occurring, and an organizational change are all events that change the premises of the assessment and require a review each time
  2. Responding to a legal revision is the legal department's job, not a reason to review the sales department's risk assessment
  3. An incident occurring in another department has nothing to do with this department, so it is not a reason for a review
  4. Since the risk assessment was decided to happen once a year, changes occurring during the year can simply be folded into the next assessment all at once, with no need for a review each time
AnswerA. Introducing a new service, a legal revision, an incident occurring, and an organizational change are all events that change the premises of the assessment and require a review each time

A regular schedule is a minimum frequency, not a substitute for reassessing when the premises change. Introducing a new service adds assets to protect and threats; a legal revision changes the controls required; an incident changes the estimate of likelihood; and an organizational change alters who is responsible and what authority they hold. An incident in another department is also information showing that a similar threat could reach this department, and responding to a legal revision, as a review of required controls, is also relevant to this department's own assessment.

Q23 | The order to start in

B in Company A's sales department is carrying out the department's first risk assessment. On hand is an information asset inventory completed last week, recording each asset's name, responsible manager, confidentiality/integrity/availability ratings, and importance. A supervisor has said, “Since the time available is limited, I want to address the highest-priority items first.” The company has regulations defining a method for computing risk level and an acceptance criterion. What should B do next?

  1. Starting with the assets of highest importance, identify risks from combinations of threat and vulnerability, and compute risk levels from likelihood and impact
  2. Gather examples of incidents that happened at other companies and apply the same countermeasures uniformly to every asset
  3. Skip using the acceptance criterion and carry out whatever countermeasure comes to mind first
  4. For every asset in the inventory, obtain quotes for countermeasure products from multiple vendors and compare cost and effectiveness
AnswerA. Starting with the assets of highest importance, identify risks from combinations of threat and vulnerability, and compute risk levels from likelihood and impact

With the inventory and importance ratings already in place, the next step is to identify threats and vulnerabilities starting from the assets of highest importance (risk identification) and compute risk levels from likelihood and impact (risk analysis). Priority is then decided by comparing against the acceptance criterion. Getting quotes for countermeasure products or applying other companies' examples uniformly would spend money without first grasping the actual size of this company's own risk. Carrying out whatever countermeasure comes to mind without using the acceptance criterion would leave important risks unaddressed.

Q24 | The treatment plan

In Company A's sales department, a risk-treatment plan was drawn up based on the risk assessment results. The plan's template records, for each risk, the countermeasure, the person responsible, the deadline, and how any residual risk after implementation will be handled. Each risk's owner drafted their own part, and B compiled them. In compiling it, B noticed that some rows had been submitted blank or with unclear wording. An excerpt of the drawn-up plan is shown below. Which entry in this plan most needs to be revised?

A社営業部 リスク対応計画(抜粋)
No  リスク                      対応策                        責任者            期限            残留リスクの扱い1   退職者IDによる不正閲覧      退職手続にID即時停止を組込み  営業事務課長      10月末          受容し記録する2   紙の契約書の紛失            施錠書庫での保管と持出し記録  営業部長          11月末          受容し記録する3   ノートPC紛失時の情報漏えい  全台のディスク暗号化          情報システム部長  12月末          受容し記録する4   顧客情報の誤送信            注意喚起の周知                未定              できるだけ早く  未検討
  1. No. 4 — Neither the person responsible nor the deadline has been decided, and how the residual risk will be handled is also undecided
  2. No. 2 — The person responsible is set at the department-head level, too senior a position for this to be effective
  3. No. 3 — The person responsible is assigned to a manager in a completely different department, not sales
  4. No. 1 — The countermeasure relies solely on an operating procedure rather than a technical means
AnswerA. No. 4 — Neither the person responsible nor the deadline has been decided, and how the residual risk will be handled is also undecided

A risk-treatment plan must always define the person responsible, the deadline, and how the residual risk will be handled, alongside the countermeasure itself. No. 4 has no person responsible decided, a deadline of “as soon as possible,” and residual risk left unconsidered — a classic case that never gets executed before the next assessment arrives. The countermeasure being an operating procedure is not itself a problem, and making a department head responsible is not invalidated just because of that seniority. Even if the party carrying it out is in another department, it is appropriate as long as the person responsible is clearly named with agreement.

Q25 | Cost-effectiveness

In Company A's sales department, a countermeasure is being considered for the risk of an information leak from losing a laptop that stores customer information. The expected loss if a leak occurs is 5 million yen per incident, and based on past experience, a loss is expected roughly once every five years, or 0.2 times a year. Option A is introducing disk encryption software, costing 300,000 yen a year, which prevents a leak almost entirely even if the laptop is lost. Option B is replacing every laptop taken outside with a model that has anti-loss features, costing 4 million yen a year. Option C is taking no countermeasure and instead paying a condolence payment to the customer when a loss occurs, with an expected annual outlay of 1 million yen. Which of the following is the most appropriate content for B to explain at the management meeting?

  1. Since the size of a risk cannot be expressed in monetary terms in the first place, comparing the cost-effectiveness of the countermeasures should be skipped altogether
  2. Since the cost of every countermeasure exceeds the expected annual loss, none of them should be carried out, and option C should simply be chosen as-is
  3. The expected annual loss is 1 million yen, and option A, which prevents a leak almost entirely for 300,000 yen a year, is the best in terms of cost-effectiveness
  4. Option B, the strongest countermeasure, should be chosen, and the size of its 4-million-yen annual cost need not be given particular weight
AnswerC. The expected annual loss is 1 million yen, and option A, which prevents a leak almost entirely for 300,000 yen a year, is the best in terms of cost-effectiveness

The expected annual loss is 5,000,000 × 0.2 = 1,000,000 yen. Option A prevents a leak almost entirely for 300,000 yen a year, achieving the effect for a cost well below the expected loss, making it the most rational choice. Option B, at 4 million yen a year, far exceeds the expected loss and has poor cost-effectiveness. Option C's expected annual outlay of 1 million yen is worse than option A, and the premise that every countermeasure's cost exceeds the loss amount is itself wrong. Presenting cost-effectiveness is basic material for management to base its judgment on.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original