Company A, a mail-order retailer, outsources customer-list data entry to Company B. The contract stipulates a confidentiality obligation and safety-management measures, and Company B has also obtained ISMS certification. One day, an employee of Company B copied working data to a personal PC and took it home, from which the names and addresses of about 5,000 customers leaked. Company B has apologized and reported the details, and says the employee involved has been disciplined. You, a leader in Company A's sales department, are to explain the response policy at an internal meeting. At the meeting, an opinion has been raised that "since Company B was contractually obligated, our company need not come forward." Which of the following is the most appropriate view of Company A's responsibility here?
Outsourcing the handling of personal data does not eliminate the outsourcer's responsibility, and Company A should take the lead in deciding on notification to affected individuals and public announcement
Since Company B was the one actually handling the information, reporting to the supervisory authority and explaining recurrence-prevention measures are both Company B's sole responsibility
Company A's responsibility is discharged by claiming damages from Company B
Since the outsourcing contract obligated Company B to implement safety management, it can be said that Company A itself need not contact the affected individuals or make a public announcement
AnswerA. Outsourcing the handling of personal data does not eliminate the outsourcer's responsibility, and Company A should take the lead in deciding on notification to affected individuals and public announcement
Even when work is outsourced, the responsibility to protect entrusted information and to supervise the outsourcing party remains with the outsourcer. Therefore Company A should take the lead in deciding on notification to affected individuals, public announcement, and explanation of recurrence prevention. Contractual obligations and the outsourcer's certification are merely one element of supervision and do not transfer responsibility. Claiming damages is a settlement between the parties and does not fulfill responsibility toward the affected individuals or society.
Q2 | Selecting a Contractor
Company A's general affairs department is selecting a new contractor for payroll processing. Since employee names, bank account numbers, and salary amounts will be handed over, it decided to add information security as a selection criterion alongside price. There are three candidate companies, and responses have been received from each on a checklist. The head of general affairs says, "above all, I want to keep costs down," but you, the leader, have organized the responses to serve as a basis for judgment. The response results are as shown in the following table. From an information security standpoint, which of the following is the most appropriate judgment?
Since Company Y plans to subcontract further, exclude it unconditionally from consideration on that point alone, regardless of its evaluation on other items
Since Company X's quoted price is the highest among the candidates, exclude it from consideration even if it satisfies all other items
Since Company Z has the lowest price and also has a responsible officer in place, select it on the premise that employee training and audit acceptance will be improved after the contract is signed
Since Company Y has a prior-approval procedure for subcontracting and accepts audits, make it a candidate after confirming how it manages its subcontractors
AnswerD. Since Company Y has a prior-approval procedure for subcontracting and accepts audits, make it a candidate after confirming how it manages its subcontractors
Although Company Y subcontracts, it has a prior-approval procedure, accepts audits, and meets the reporting deadline, so it can be a candidate once its management of subcontractors is confirmed. Excluding Company X on price alone misuses the selection criteria. Subcontracting itself is not a disqualifying factor; the key point is whether approval and management are in place. Company Z does not accept audits and its subcontracting details are unclear, so it is inappropriate to sign the contract, with no means of verification, in the hope of improvement afterward.
Q3 | Subcontracting Approval
Company A has outsourced maintenance of its core system to Company B. The contract states, "When subcontracting is to be performed, prior written approval from the outsourcer must be obtained." One afternoon, a representative of Company B called you, Company A's information security leader, saying, "We are short-staffed due to a busy period and want to have our partner Company C help with part of the work starting tomorrow. It's urgent, so could we get your verbal okay?" Company C's work requires connecting to the maintenance environment, which contains Company A's customer data. Company B explains, "We have a long relationship with Company C and there is no problem." What should you do first?
Have Company A contract directly with Company C, bypassing Company B, to structure it so that it does not count as subcontracting
Since the proposal of subcontracting itself constitutes a breach of contract, immediately terminate the outsourcing contract with Company B
Have them submit in writing the name and location of subcontractor Company C, the scope and duration of the work, the type of information handled, and whether Company C is under an equivalent confidentiality and safety-management obligation by contract
Since it is urgent, give verbal approval on the spot by phone, and receive the written document listing the subcontractor's name and work scope together after the work has begun
AnswerC. Have them submit in writing the name and location of subcontractor Company C, the scope and duration of the work, the type of information handled, and whether Company C is under an equivalent confidentiality and safety-management obligation by contract
As a principle, approval for subcontracting should be given only after receiving, in writing, the information needed to judge it. First confirm the subcontractor, the scope of work, the information to be handed over, and whether the subcontractor is under an equivalent obligation. A verbal approval leaves the scope vague and no evidence. The proposal itself is a procedure permitted under the contract and not a violation, so terminating the contract is excessive, and having Company A contract directly with Company C would break the maintenance division of responsibility and does not substitute for the approval decision at hand.
Q4 | Contract Clauses
Company A is newly outsourcing its inquiry help-desk operations to Company D, and you, the leader, reviewed the contract draft forwarded from the legal department. The draft defines a confidentiality obligation, a prohibition on use for purposes other than intended, prior approval for subcontracting, and an obligation to report in the event of an incident. On the other hand, there is no provision for returning or deleting entrusted data at contract termination, nor any provision for accepting an audit by which Company A can confirm the state of implementation. The legal department staff member says, "since this is their standard contract, adding clauses would probably be difficult." The outsourced work will involve customers' names and contact information. What is the most appropriate response for you to take?
Since it is the other party's standard contract, sign it as presented without change, and verbally request deletion of the data at the time the contract ends
Before signing, negotiate to add, via a memorandum or similar, the return or deletion of data at contract termination and acceptance of confirmation by document or on-site visit
Since the missing clauses represent significant risk, abandon this outsourcing arrangement altogether and proceed by performing all the work in-house
Omit the acceptance of audits since it is not used in practice, and only add, via a memorandum, the return or deletion of data at contract termination
AnswerB. Before signing, negotiate to add, via a memorandum or similar, the return or deletion of data at contract termination and acceptance of confirmation by document or on-site visit
Both the return/deletion of data at termination and the acceptance of audits are indispensable clauses for supervising the contractor, and the right approach is to negotiate to add them before signing. Requesting deletion verbally after signing has no contractual basis and provides no proof. Omitting audit acceptance removes any means of confirming a suspected problem. The absence of these clauses is itself a problem that negotiation can resolve, and cancelling the outsourcing is an excessive response that fails to weigh the business need.
Q5 | Annual Confirmation
Company A continues a practice of sending contractors a checklist once a year, requesting responses on the state of implementation along with supporting evidence. This year too, a response arrived from Company B, the data-entry contractor, and when you, the leader, reviewed it, every item was answered "implemented." However, among the requested evidence, only the item concerning annual training for employees was not submitted. Company B's staff contact changed partway through the year, and handover from the previous contact appears to have been incomplete. The responses and evidence status are as shown in the following table. What should be done first?
Since subcontracting was answered as "none," remove the subcontracting clause from next year's contract
Since the reliability of the response is doubtful, conduct an unannounced on-site inspection and re-verify every item on the spot
Request that supporting evidence, such as attendance records, for the claimed training be submitted by a set deadline
Since all responses are "implemented," simply keep them on file as a record and conduct no further confirmation until next year
AnswerC. Request that supporting evidence, such as attendance records, for the claimed training be submitted by a set deadline
Since the purpose is verification, the responses and evidence only have meaning once cross-checked. Since one item's evidence is missing, the proper order is first to request that evidence by a set deadline. Simply filing the responses leaves only a record and does not constitute supervision. Jumping straight to an on-site inspection over one missing item skips steps, and the circumstances of the staff change have not even been confirmed yet. Since subcontracting could arise in the future, removing the clause would invite unnecessary risk.
Q6 | Duty of Supervision
Company A's human resources department is considering outsourcing the tabulation and analysis of a company-wide workplace-environment survey to outside Company B. The data to be handed to Company B includes employees' names, affiliations, and survey responses. A staff member in HR asked you, the leader, "since data is being handed to an outside party, don't we need to obtain individual consent from every employee?" The outsourcing plan calls for defining confidentiality and safety-management measures in the contract and specifying the work location and storage method. Which of the following is the most appropriate explanation?
Since the contractor is also subject to the Act on the Protection of Personal Information, all management of the data after handover is entirely the contractor's responsibility, and the outsourcer has no duty of supervision
Providing personal data as part of outsourcing does not constitute third-party provision and does not require the individual's consent, but the outsourcer has a duty to supervise the contractor
Personal data that has not been pseudonymized or anonymized can never be handed to an outside party under any circumstances
Even outsourcing constitutes third-party provision, so outsourcing cannot proceed without obtaining individual consent from every employee
AnswerB. Providing personal data as part of outsourcing does not constitute third-party provision and does not require the individual's consent, but the outsourcer has a duty to supervise the contractor
Providing data in connection with outsourcing the handling of personal data does not constitute third-party provision, and the individual's consent is not required. Instead, the outsourcer is placed under a duty of necessary and appropriate supervision of the contractor. The choice that consent is mandatory confuses outsourcing with third-party provision. The fact that the contractor is also subject to the law does not negate the outsourcer's duty of supervision. There is also no rule uniformly barring the release of non-pseudonymized data to outside parties.
Q7 | Division of Responsibility
Company A's sales department uses a cloud file-sharing service (SaaS) to share quotations and proposals. The service provider has obtained ISMS certification and publishes its data center management structure. One day, a client contacted the company saying, "your quotation can be found in an internet search." Investigation revealed that when a staff member created a sharing link, it was issued with the default setting of "anyone with the link can view," and it had been reposted on an outside blog. A sales department staff member argues, "the problem lies with the provider's service, so the provider should be asked to investigate the cause and prevent recurrence." What is the most appropriate response here?
Since there appears to be a deficiency in the scope covered by the provider's certification, file a formal written complaint with the certification body
Since the use of cloud itself is the cause, ban the use of cloud services company-wide and move back to in-house servers
Since the user bears no responsibility when using SaaS, proceed to seek damages from the provider
Since the public-scope setting falls within the user's area of responsibility, review Company A's own default settings, link-issuance authority, and inspection practices
AnswerD. Since the public-scope setting falls within the user's area of responsibility, review Company A's own default settings, link-issuance authority, and inspection practices
In cloud services, responsibility is divided between the provider and the user, and for SaaS, the user account, access rights, public-scope settings, and the content stored are the user's responsibility. Since this incident stemmed from the user's own settings, it is correct to fix the default settings, the authority to issue links, and the inspection practice. There is no problem with the provider's equipment or certification, so filing a complaint or seeking damages is based on a mistaken premise. A total ban does not address the cause and also disregards the business need.
Q8 | Clause Comparison
In renewing its contract with logistics contractor Company E, Company A organized the contract's clauses into a list. The review found that, while most necessary clauses are present, there are some clauses that are missing or limited. Company E handles the names and delivery addresses of Company A's customers and plans to subcontract part of the delivery work to a partner company. You, the leader, are organizing what to request in the renewal negotiation based on this list. The clause review results are as shown in the following table. Which of Company A's responses here is inappropriate?
Since reporting within 72 hours of discovery may delay the initial response, consider separately setting a shorter deadline for the first report
Since a confidentiality obligation is defined, it is sufficient for the contractor to manage its subcontractors, and Company A need not learn the subcontractor's name or scope of work
Since there is no provision for the handling of data at termination, request that the scope and deadline for return or deletion, and submission of a completion report, be added to the renewed contract
Since on-site visits are not permitted, decide in advance the specific types of evidence to be submitted for confirmation by document
AnswerB. Since a confidentiality obligation is defined, it is sufficient for the contractor to manage its subcontractors, and Company A need not learn the subcontractor's name or scope of work
Since subcontracting widens the range through which information can travel, learning the subcontractor's name, scope of work, and the information it will handle is indispensable to the decision on prior approval, and omitting this on the grounds of a confidentiality obligation is inappropriate. It is reasonable to request an addition if the handling of data at termination is undefined, and specifying in advance what evidence to request by document is a realistic way to compensate when on-site visits are not allowed. Considering a separate, shorter deadline for the first report is also an appropriate way to speed up the initial response.
Q9 | Initial Incident Report
At 6 p.m. on a Friday, you, Company A's information security leader, received a call on your cell phone from a representative of contractor Company B. "A laptop used for the work is missing. It may have been left somewhere in our office, so it isn't confirmed as lost yet," the call said. The laptop may contain working files of customer data entrusted by Company A. Company B's representative says, "we'd like to make a formal report once things are clear." Under Company A's contract, a first report must be made within 2 hours of discovery, including a possible incident, and the receiving point is the information systems department's incident desk. What should be done first?
Instruct Company B's representative not to inform anyone, inside or outside the company, until the facts are confirmed
Since the loss is not yet confirmed, wait until Monday morning to report to a superior, and quietly monitor the situation without making contact in the meantime
Immediately submit a first report to the company's own incident desk, and request that Company B submit a formal first report in the prescribed format and identify the information on the laptop
Without waiting until the following week, go to Company B's office yourself and search for the laptop together with the representative
AnswerC. Immediately submit a first report to the company's own incident desk, and request that Company B submit a formal first report in the prescribed format and identify the information on the laptop
Under the contract, the first report is to be made at the stage of a possible incident, and a delay in the initial response widens the damage. The correct approach is to first connect to the company's own desk, and in parallel require the contractor to submit a formal first report and identify the stored information. Waiting for confirmation or instructing silence are both errors that keep the reporting channel from functioning. Going to the site alone puts off the top-priority action of mobilizing the internal response structure.
Q10 | Deletion at Termination
Company A's six-month outsourcing of campaign help-desk operations to Company B has ended. The work handled the names, addresses, and phone numbers of about 20,000 applicants. An email arrived from Company B stating, "All work has been completed. The entrusted data will be handled appropriately in accordance with our regulations." The contract stipulates that entrusted data must be returned or deleted at contract termination and that a completion report must be submitted. Upon checking with Company B, it explained that, in addition to the working data, daily backups are stored on a separate system. What is the most appropriate response for Company A?
Since whether deletion was carried out can be confirmed at next year's internal audit, for now simply keep a record of having received the report email
After confirming that the backups and working copies are also included in scope, request submission of a certificate of deletion by a set deadline
Since Company B is certified and trustworthy, end the outsourcing without requesting submission of a certificate of deletion
Since the backups were created by Company B for its own operational purposes, there is no need to include them in the scope of deletion
AnswerB. After confirming that the backups and working copies are also included in scope, request submission of a certificate of deletion by a set deadline
Return and deletion at contract termination is only complete once it covers not just the working data but also backups and copies. It is appropriate to make the scope clear, set a deadline, and obtain evidence in the form of a completion report. Omitting the report on the grounds of trust removes any means of confirmation later. Excluding backups from scope leaves information persisting indefinitely. Waiting until the audit leaves an undeleted state unaddressed for a long period.
Q11 | Purpose of Training
Company A conducted a targeted-attack email training exercise for the first time. When a training email disguised as a routine business message was sent to all employees, the open rate was 22%, while reports to the reporting desk reached only 6%. At the meeting where results were shared, a department head requested, "please give me a list of names of employees who opened it. I want to name and coach them individually and reflect it in performance reviews." You, the leader, feel you need to explain the purpose of the training again. The training is planned to continue once a year going forward. What is the most appropriate response for you to take?
Provide the department head with a list of names of employees who opened the email as requested, and cooperate with individual coaching and reflecting it in performance reviews
From next time, make the training email obviously identifiable as training so that the open rate goes down
Since a high open rate lowers morale within the company, do not publish the results and have only the person in charge keep them
Do not provide names; share the results as department-level trends, and use the method that caused the most opens as material for education that establishes reporting behavior
AnswerD. Do not provide names; share the results as department-level trends, and use the method that caused the most opens as material for education that establishes reporting behavior
The purpose of the training is to establish the behavior of not opening a suspicious email and promptly reporting it when noticed, and to check whether the reporting channel functions. Identifying and punishing those who opened it will make people hide the fact next time, so reports will stop coming in during a real attack. Concealing the results does nothing to improve the education, and deliberately making the email easy to spot does not prepare anyone for a real attack.
Q12 | Training Metrics
Company A conducted its second targeted-attack email training exercise and tabulated the results by department. The training email was disguised as a routine business message, and both opens and reports were measured. The report rate is the number of reports as a proportion of emails sent, and the time to first report is the time until the first report reaches the desk. The company-wide target was "an open rate of 15% or below," but you, the leader, believe the open rate alone should not be used to judge good or bad. The tabulated results are shown in the following table. Which of the following is the most appropriate reading of the results?
The company-wide open rate is below the 15% target and the report rate has also improved, so all future training should be discontinued
For general affairs and development, whose open rate is low but whose report rate is also low and first report is slow, prioritize communicating the reporting desk and reporting procedure
Since general affairs has the lowest open rate, it can be said to be in the best state, and other departments should be evaluated as needing to emulate general affairs' approach
Since sales has the highest open rate, sales staff should undergo retraining including disciplinary action
AnswerB. For general affairs and development, whose open rate is low but whose report rate is also low and first report is slow, prioritize communicating the reporting desk and reporting procedure
Even if the open rate is low, if no one reports it, damage progresses unnoticed in a real attack. General affairs and development both have a 5% report rate and a first-report time of over 150 minutes, so communicating the reporting channel is the top priority. Judging general affairs as a model based on the open rate alone confuses the metric. Punishing those who opened the email discourages reporting. The company-wide open rate is 52÷310, about 16.8%, which exceeds the target, so the premise for stopping training is mistaken.
Q13 | Scope of Education
Company A conducts annual information security training via e-learning, targeting regular employees only. In practice, temporary staff handling reception duties and contractor employees stationed on-site for development are also able to connect to the internal network and view customer data. A recent internal audit pointed out that "some of those who have access to information are not covered by the training." HR has raised the view that "since temporary staff and contractor employees are not our employees, isn't training their responsibility, of the staffing agency or the contractor?" You, the leader, are to present a corrective policy. What is the most appropriate approach?
For temporary staff, forgo in-house training and address it solely by reducing the scope of information they can view
Judge that, since contractor employees are under a confidentiality obligation via the outsourcing contract, in-house training is not particularly necessary
Leave them out of scope because of the different employment type, and verbally convey that training is left to the staffing agency or contractor
Provide training and pledges based on the company's own regulations to temporary staff and contractor employees as well, according to the extent of their access to the company's information
AnswerD. Provide training and pledges based on the company's own regulations to temporary staff and contractor employees as well, according to the extent of their access to the company's information
Anyone who has access to the company's information needs training and a pledge based on the company's own regulations, regardless of employment type. Training by the staffing agency or contractor does not cover the company's own specific procedures, so it cannot be substituted for with a verbal request. Narrowing access rights is an effective measure but does not substitute for informing people of the regulations. Even with a contractual confidentiality obligation, a person cannot comply without knowing the specific procedures.
Q14 | Training on Change
Company A revised its regulation on taking information outside the company. Under the revision, removal via USB drive, including personal drives, is now prohibited in principle, and sending files outside the company now requires application and approval from a supervisor via a designated cloud service. The secretariat posted the revised regulation to the intranet's regulation library and set the effective date as the 1st of the following month. However, at a meeting of on-site leaders, there were repeated comments such as "I didn't know it had been posted" and "I've never seen the new application screen." There are 3 weeks until the effective date. What should be done first?
Communication is already complete once posted to the regulation library and published internally, so no further action is particularly needed
Since it turned out the field did not know about it, cancel the revision of the regulation itself and revert to the previous operation
Before the effective date, deliver a summary of the changes, the effective date, and the new application procedure to those affected, and hold a session to confirm understanding
After the effective date, identify violators of the regulation and provide individual coaching and cautioning to those concerned
AnswerC. Before the effective date, deliver a summary of the changes, the effective date, and the new application procedure to those affected, and hold a session to confirm understanding
A regulatory revision is a moment when the premises change, and on-site operations only actually change once training on the change is provided. The proper order is to deliver the changes, the effective date, and the new procedure before it takes effect, and to confirm understanding. Treating mere posting as complete communication does not match reality. Looking for violators after the fact holds people accountable without ever creating conditions in which they could comply. Cancelling the revision does not address the underlying cause, which is insufficient communication.
Q15 | Annual Plan
You, the leader at Company A, organized this fiscal year's information security education annual plan and results into a list. Upon organizing it, you found that some categories have been carried out while others have no plan at all. System administrators handle privileged IDs, and on-site contractor employees are in a position to view customer data. In creating next year's plan, you need to decide what to tackle first given limited work-hours. The organized results are shown in the following table. Which of the following is the most appropriate revision for next year's plan?
Set increasing general-employee education from once to twice a year as the top-priority item in next year's education plan
Prioritize adding, to next year's plan, education for system administrators and for temporary/contractor employees, for which no plan currently exists at all
Since new employees have a 100% attendance rate and it has become established, discontinue the in-person training for new employees altogether next year
Abolish the in-person training for managers, which has the lowest attendance rate, and consolidate all education for managers into e-learning
AnswerB. Prioritize adding, to next year's plan, education for system administrators and for temporary/contractor employees, for which no plan currently exists at all
The table shows that no education plan exists at all for system administrators who handle privileged IDs and for temporary/contractor employees who have access to customer data. Resolving the fact that the highest-risk group is out of scope is the top priority. The 88% attendance rate for managers is an issue to improve through follow-up, and abolishing the training runs counter to that. Discontinuing new-employee training because of its 100% attendance rate would send next year's new employees into their jobs without any training. Increasing the frequency is a lower priority than filling the gap in coverage.
Q16 | Comprehension Analysis
Company A administers a comprehension test at the end of its annual training, and this year too the company-wide results were tabulated by topic. The overall average correct-answer rate rose 2 points from the previous year. On the other hand, looking by topic, the gap is large, and it turns out that one particular topic alone has remained low. In the field, near-miss reports concerning removal via personal USB drive continue to be filed. You, the leader, are analyzing the results to reflect them in next year's education plan. The tabulated results are shown in the following table. What should be done first?
Since the correct-answer rate for reporting suspicious-email destinations has risen significantly, discontinue education and questions on that topic from next year and redirect that time to other topics
For the removal-application procedure topic, whose correct-answer rate has remained low, check whether the materials' explanation is insufficient and whether the actual application procedure itself is hard to use
Remove questions on the topic with a low correct-answer rate from next year's test, raising the overall average correct-answer rate
Since the overall average correct-answer rate has risen from the previous year, use the same materials and the same structure again next year
AnswerB. For the removal-application procedure topic, whose correct-answer rate has remained low, check whether the materials' explanation is insufficient and whether the actual application procedure itself is hard to use
Looking by topic, only the removal-application procedure is low at 41%, and it has also fallen from the previous year, which is consistent with the near-miss reports. The first step is to check whether the materials' explanation is insufficient or whether the procedure itself is hard to use. Leaving it as is because the average rose would leave this weak point in place. Removing the low-scoring questions only dresses up the numbers without changing reality. Even a topic that has improved will regress if it is not repeated.
Q17 | Tabletop Exercise
Company A created an incident-response procedure manual assuming a ransomware infection, but has not run a single exercise in the six months since creating it. The manual specifies the initial contact point, who decides on network isolation, and who decides on public disclosure, among other things. A live exercise that actually halts the business system is difficult to carry out because of the major impact on the production line. Outsourcing the exercise was considered, but this year's budget makes it difficult. You, the leader, still want to check whether the manual can actually be used. What is the most appropriate approach?
Since simply reading through the manual together is meaningless, wait to run any exercise until the budget can be secured, and then run a live exercise that halts the actual production business system
It is sufficient for the exercise to be run by the information systems department alone; participation by business departments is not necessary
Distribute a hypothetical scenario, gather the people concerned, and run a tabletop exercise in which each person confirms in turn the actions and decisions they would take next, surfacing outdated contact information and gaps in who is responsible for decisions
If a live exercise cannot be done, skip exercises altogether and substitute distributing the manual to everyone
AnswerC. Distribute a hypothetical scenario, gather the people concerned, and run a tabletop exercise in which each person confirms in turn the actions and decisions they would take next, surfacing outdated contact information and gaps in who is responsible for decisions
A tabletop exercise can be run without stopping the system, keeps cost down, and can surface gaps in the manual such as outdated contact information or missing decision-makers. The value of an exercise lies not in performing it smoothly but in surfacing what is not yet working. Merely distributing the manual does not reveal whether the procedure functions, and waiting for budget while doing nothing is also risky. Since business departments are involved in decisions to halt operations and in customer communication, an exercise limited to the information systems department alone is insufficient.
Q18 | Training Records
At Company A, the person in charge managed information security training attendance records in a spreadsheet file on a personal PC. When that person transferred to another role and organized the files, it turned out that two years' worth of attendance records were missing. Unfortunately, a request arrived from outsourcing client Company F asking to "submit records showing the state of training provided to your employees." The training itself has been conducted every year, and the materials and announcement emails from that time still exist. You, the leader, need to address both this submission and future record management. What is the most appropriate approach?
Since the training itself has been conducted every year even though the records are gone, it is sufficient to explain verbally that it was carried out
Since the records exist only for audits and client confirmation, compile them freshly each time a request is received
Define in regulation who is responsible for keeping the records, where, and for how long, changing to a system that does not depend on one individual, and present Company F with the records that do exist along with a recurrence-prevention plan
Recreate a list of past attendees for the two missing years relying on the memory of attendees and others involved, submit it to Company F as the actual attendance record from that time, and continue handling future requests the same way
AnswerC. Define in regulation who is responsible for keeping the records, where, and for how long, changing to a system that does not depend on one individual, and present Company F with the records that do exist along with a recurrence-prevention plan
Training records are evidence substantiating that training took place, and the proper approach to preventing recurrence is to define who is responsible for keeping records, where, and for how long, so it does not depend on one individual. For the submission, honestly presenting what records do exist along with a recurrence-prevention plan is the sincere response. A verbal explanation is not evidence. Submitting a list recreated from memory as if it were the actual record is creating a record that misrepresents the facts, and compiling records fresh each time a request comes in likewise strips them of their value as evidence.
Q19 | Training Trend
Company A has run targeted-attack email training for three consecutive years, reflecting the results in education each time. In the first round, many employees opened the email and almost no one reported it, so the company focused on communicating the reporting desk and explaining that reporting would not lead to blame. Separately from the training, the company also records the monthly average number of suspicious emails that employees actually receive and report to the desk. At the next committee meeting, you, the leader, are to report the 3-year trend to management. The trend is shown in the following table. What is the most appropriate content for the report?
Since the open rate is the only metric worth evaluating, report that no results have been achieved until the open rate falls below 10%
Since the report rate has risen but the open rate has not yet reached 0%, report that the three years of training have had no effect
Since the number of reports of suspicious emails actually received by employees keeps increasing, report that employee information security awareness is actually declining
Report that, along with the decline in the open rate, the rise in report rate and the shortening of time to first report have continued, and that actual suspicious-email reports have also increased, indicating that reporting behavior is becoming established
AnswerD. Report that, along with the decline in the open rate, the rise in report rate and the shortening of time to first report have continued, and that actual suspicious-email reports have also increased, indicating that reporting behavior is becoming established
Not only has the open rate declined, but the report rate has risen, the time to first report has shortened, and actual suspicious-email reports have increased — together these indicate that the behavior of reporting upon noticing something is becoming established. The rise in actual report counts should be read as previously overlooked incidents now reaching the desk, not as declining awareness. Views that treat the open rate as the sole metric, or that deem there to be no effect unless it reaches 0%, both misread the purpose of the training.
Q20 | Reporting to Management
At Company A's annual information security committee meeting, you, the leader, report on the state of education. Past reports have centered on facts of implementation such as "e-learning was conducted, and the attendance rate was 97%," and management has repeatedly asked, "so has the company actually gotten stronger?" Next year, you are considering outsourcing part of the training and remaking the materials for topics with low comprehension, both of which require budget. On hand, you have the attendance rate, the comprehension test's correct-answer rate by topic, the training's report rate and time to first report, and the trend in the number and type of incidents. What is the most appropriate way to report to the committee?
Since management does not need fine detail, skip the trend in metrics, next year's plan, and the required budget, and report only the conclusion that no major problems have occurred
Present the attendance rate along with the comprehension test's correct-answer rate by topic, the training's report rate and time to first report, and the trend in incident count and type, and propose what to change next and what resources are needed
Since the effect of education cannot be expressed in numbers, report only the number of sessions held and the number of participants
Show only the attendance rate, and explain that falling short of 100% is due to low awareness in the field
AnswerB. Present the attendance rate along with the comprehension test's correct-answer rate by topic, the training's report rate and time to first report, and the trend in incident count and type, and propose what to change next and what resources are needed
A report to management only leads to a decision once it shows not just the fact of implementation but how the metrics have moved, what to change next, and what is needed to do so. Showing only the attendance rate and blaming low awareness in the field offers no improvement plan. Effect can be approximated through metrics, and count and participant numbers alone give no basis for judgment. A conclusion of "no problems" alone will not secure the needed budget or company-wide mandate.
Q21 | Audit Independence
Company A conducts an internal information security audit once a year. This year's audit scope includes the access-rights management mechanism that the information systems department itself designed and operates. At a meeting to decide who will perform the audit, the secretariat proposed, "since the information systems department knows the mechanism best, it would be efficient to have that department's chief handle the audit." The chief himself also says, "I could check it quickly." You, the leader, have concerns about this proposal. What is the most appropriate approach?
Since internal audit is merely a formal activity, skip it this time and substitute the results of an external examination by a certification body
Since independence is merely a formal requirement, proceed with the secretariat's proposal as is, and it is sufficient to note in the audit report that independence was considered
Since the staff member most familiar with the mechanism is more likely to find deficiencies, proceed with the secretariat's proposal and have the information systems department's chief handle it
Have someone who does not belong to the audited department, the audit department, or an outside specialist take charge, with the information systems department in the position of providing explanations and evidence
AnswerD. Have someone who does not belong to the audited department, the audit department, or an outside specialist take charge, with the information systems department in the position of providing explanations and evidence
When those who built and operate a mechanism audit it themselves, inconvenient facts can be overlooked and objective judgment becomes difficult, so independence is required of the auditor. Familiarity is not a requirement for the auditor; that familiarity can instead be put to use on the explaining side. Independence cannot be secured merely by noting it in the report. Internal audit is an activity by which the organization checks itself and cannot be replaced by an external examination.
Q22 | Audit Preparation
Company A is starting internal information security audits this year for the first time, and a staff member from general affairs has been appointed as auditor. That staff member says, "I plan to visit each department and raise anything that catches my attention on the spot." The company has an information security regulation and various procedure manuals, and contracts with outsourcing partners include clauses on safety management. Audit results are to be reported to management, and corrective action requested for any findings. You, the leader, are concerned that the audited departments will not find this approach convincing. What should be done first?
Obtain another company's audit report and adopt the findings written there as-is as this company's own findings
Visit each department, list what catches your attention, and select the items that seem important as findings
Define in advance the audit's scope and the audit criteria against which good and bad will be judged (the company's own regulations, procedure manuals, contract clauses, laws)
Since notifying departments in advance lets them prepare, conduct the audit as a surprise without notifying the scope or schedule, citing only what is observed on the spot as findings
AnswerC. Define in advance the audit's scope and the audit criteria against which good and bad will be judged (the company's own regulations, procedure manuals, contract clauses, laws)
An audit is an activity that checks whether what has been decided is being followed, judged against a set of criteria. Unless the scope and audit criteria are defined beforehand, findings become the auditor's subjective impressions, and the audited department cannot be convinced. Listing whatever catches one's attention tends to produce findings with no basis. Notifying the scope in advance is meant to let evidence be gathered, not to assist concealment. Reusing another company's findings as-is does not correspond to this company's actual situation.
Q23 | Prioritizing Findings
Company A manages internal-audit findings in a list, checking the category, corrective deadline, and progress each month. The categories are "nonconformity," which fails to meet a regulation or requirement, and "opportunity for improvement," which is not a violation but could be done better. Today is October 20, and you, the leader, have organized the situation ahead of the progress meeting. Some items are not progressing, and some have even passed their deadline. The current status is shown in the following table. Which item should be tackled first?
Concentrate on completing first the procedure development for No.3, which still has days remaining until its deadline
Begin work on deleting the retired employee's account for No.1, which is past its deadline and still has no one assigned
For No.5's issue of documents being left out in the meeting room, issue a renewed company-wide caution notice
Begin work on aligning the regulation's wording for No.4's training-record retention period, ahead of other items
AnswerB. Begin work on deleting the retired employee's account for No.1, which is past its deadline and still has no one assigned
No.1 is a nonconformity, and even past its September 30 corrective deadline no one has yet been assigned; a retired employee's account remaining active leads directly to unauthorized use. It should therefore be tackled with the highest priority. No.2 and No.3 are within their deadlines and in progress, No.4 is an opportunity for improvement whose deadline is the next revision cycle, and No.5 has already been corrected — none of these has a reason to be addressed first. Priority should be judged by combining category, deadline, and progress.
Q24 | Correction and Prevention
Company A's sales department received a finding in last year's internal audit that "access rights in the former department of a transferred employee had not been removed." Sales removed the rights of the individual concerned on the spot, reported to the audit department that "the staff member involved was cautioned," and treated it as corrected. Yet this year's audit produced the same finding on 3 separate cases. Investigation showed that transfers are processed in the HR system, but removal of access rights operates on a basis where each department's staff apply for removal whenever they happen to notice, and the procedure manual does not describe a removal step at all. You, the leader, want to stop the recurrence this time for good. What is the most appropriate approach?
Since it has recurred despite last year's caution, discipline the staff member who neglected to remove the former access rights, based on the work rules
Perform a batch inventory and removal of unnecessary access rights right before the audit each year, so as to avoid the finding the following year too
Since this finding recurs every year, strongly request the audit department to exclude it from findings as unavoidable in practice
Build removal of former access rights into the transfer procedure as a mandatory step, and confirm its execution through a quarterly inventory
AnswerD. Build removal of former access rights into the transfer procedure as a mandatory step, and confirm its execution through a quarterly inventory
Cautioning an individual only corrects the immediate deficiency and does not amount to prevention that changes the system so the same thing cannot happen again. Only by building the removal step into the procedure and confirming it through regular inventory does recurrence actually stop. Discipline leaves the root cause — the missing procedure step — in place. Requesting exclusion from findings merely hides the risk, and tidying up only right before the audit leaves the residual rights in place for the rest of the period.
Q25 | How to Receive an Audit
Company A's sales department is scheduled to undergo an internal audit next week covering "removal and storage of customer information." In practice, some staff in sales, finding the official application procedure cumbersome, have been saving customer lists to personally contracted cloud storage without obtaining a supervisor's approval. The sales department head instructed at a department meeting, "since a poor evaluation from the audit would be a problem, don't bring that up unless asked." You, the leader, are unsure whether to go along with this instruction. Submission of a corrective plan will be required after the audit. What is the most appropriate approach?
Advise the department head to explain the actual situation and the number of cases without concealment, together with the underlying cause — that the official procedure is hard to use — and a corrective plan
Delete all files on the personally contracted cloud storage before the audit date, and explain as though that practice never existed
Follow the department head's instruction, answer only what is specifically asked in a perfunctory way, and do not raise the actual situation from your side
Since the audit is merely a formality, limit yourself to submitting the requested records, and exclude staff who know the actual situation from attending
AnswerA. Advise the department head to explain the actual situation and the number of cases without concealment, together with the underlying cause — that the official procedure is hard to use — and a corrective plan
The role of the audited department is to present the facts, including the underlying cause, so it can lead to correction. Concealment is often discovered anyway through cross-checking with evidence, and if it is not discovered, the risk is simply left in place. In this case there is an underlying cause — the procedure being hard to use — and unless that is presented, no effective correction can result. A perfunctory response, an account pretending nothing happened, or excluding those who know the facts, all keep the audit from functioning.
Q26 | Audit Trail
In Company A's internal audit, the auditor interviewed a staff member in the business department about operating practices and also checked for supporting records. The staff member explained for every item that "it is carried out according to regulation," but the state of records varied by item. The auditor believes that explanations and records must be cross-checked to reach a judgment. The results of the check are shown in the following table. What is the most appropriate judgment for the auditor to make?
For items lacking records, have the auditor interview the staff member in detail and create a new ledger, treating it as-is as the audit trail
Since the field explains that it is being carried out, judge there to be no problem regardless of whether records exist
For the application form with a blank approval field and for removals relying on memory with no ledger, cite insufficient audit trail as a finding, since implementation cannot be confirmed
For entry/exit records and training, for which records do exist, likewise cite a finding because the staff member's explanation alone is insufficient
AnswerC. For the application form with a blank approval field and for removals relying on memory with no ledger, cite insufficient audit trail as a finding, since implementation cannot be confirmed
An audit is conducted based on facts, with verbal explanations substantiated by cross-checking against records. A blank approval field means the fact of approval cannot be confirmed, and the absence of a ledger means removal activity cannot be traced, so these should be cited as findings for insufficient audit trail. Citing items for which adequate records already exist as findings as well has no basis. Having the auditor create records to serve as the audit trail runs counter to the auditor's role of independently verifying.
Q27 | Closing the Loop on Improvement
Company A conducts an internal information security audit every year and produces an audit report. However, the report is merely kept on file by the secretariat, with no venue for reporting it to management, and it is not reflected in the following year's plan or budget. As a result, nearly the same findings appear year after year, and voices in the field say "nothing ever changes anyway." This year's audit has also just finished, and you, the leader, have just received the report. What is the most appropriate approach?
Judge that, since the audit results are a matter of on-site operations, there is no need to report them to management
Since an audit is a checking activity, consider PDCA to have completed one cycle simply by having performed the audit
Since the same findings appearing every year is due to the auditor's fixed perspective, rotate the audit items each year so the same findings do not recur
Establish a management review venue where management reviews the audit results, incident occurrences, and degree of goal achievement, and reflect its decisions in next year's plan and resource allocation
AnswerD. Establish a management review venue where management reviews the audit results, incident occurrences, and degree of goal achievement, and reflect its decisions in next year's plan and resource allocation
An audit corresponds to Check, and PDCA only actually turns once the results progress to Act — a review by management that feeds into the next plan. Establishing a management review and connecting it to decisions on policy and resource allocation is the correct approach. Without escalating to management, budget and mandate cannot be obtained, and improvement stalls. Rotating items to avoid repeat findings merely hides the fact that the underlying issue has not been fixed.
Q28 | External Examination
At the request of a client, Company A is pursuing ISMS certification for the first time. The secretariat staff member proposes, "since the goal is to pass the examination, let's model the regulation on another company's polished one to make it look ideal, and also redo the records to look neat for the examination." Actual operations are looser than the draft regulation in places — for example, entry/exit records are entered in weekly batches rather than every time. The examination checks both the regulation and actual operations. You, the leader, have concerns about this approach. What is the most appropriate approach?
Abolish the regulation to match on-site operations, leaving matters to case-by-case judgment
Shape the regulation to match what the company can actually carry out, so that the records generated by day-to-day operations can be submitted as-is as evidence
For the parts where regulation and operations diverge, operate according to the regulation only during the examination period, then revert to the previous operations once the examination ends
Since the goal is to pass the examination, draft a new, ideal-looking regulation, tidy up the records for the examination as well, and submit them
AnswerB. Shape the regulation to match what the company can actually carry out, so that the records generated by day-to-day operations can be submitted as-is as evidence
An examination checks whether what the organization itself has defined is being followed, so an ideal regulation that cannot actually be carried out becomes a cause of nonconformity. Since records from everyday operations become the evidence as-is, keeping them in a form that persists day to day is the best preparation. Records reworked for the examination do not represent the facts. Following the regulation only during the examination just means the deficiency returns afterward, and abolishing the regulation eliminates the standard itself.
Q29 | Reading the Report
Company A underwent an external examination and received a report from the examination body. The report categorizes findings, and the required response and deadline differ by category. The secretariat staff member says, "since there are many items, perhaps we should only address the ones with an explicit deadline." You, the leader, decide to organize what each category means before deciding on a response policy. The report's contents are shown in the following table. Which of Company A's responses would be inappropriate?
Since the 5 opportunities for improvement have no deadline and response is optional, do not keep any record of them and do not even consider them
Establish an in-house mechanism to follow up on whether corrective actions were carried out by their deadlines
Since the 3 minor nonconformities also require correction, assign a person in charge and an internal deadline to each
For the major nonconformity, begin cause analysis immediately and prepare to submit a corrective plan within 30 days
AnswerA. Since the 5 opportunities for improvement have no deadline and response is optional, do not keep any record of them and do not even consider them
An opportunity for improvement does not currently violate a requirement, but it points to room for reducing risk, so it is appropriate to keep a record, judge its priority, and decide whether to act on it. Failing to even consider it and keeping no record at all leaves the seed of a future nonconformity unaddressed. Immediate action on the major nonconformity, assigning owners and deadlines to the minor nonconformities, and establishing a follow-up mechanism are all appropriate responses.
Q30 | Judgment to Escalate
Company A's internal audit produced a nonconformity finding that "the core system's operation logs are retained for only one week, so if fraud is suspected there is no way to trace back." Correcting this requires additional storage and a configuration change, estimated to cost several million yen. The information systems department responded, "we cannot proceed since it is not budgeted for this fiscal year," and only 2 months remain until the corrective deadline. You, the leader, have requested action three times with no change in the situation, and feel this cannot be resolved through inter-departmental coordination alone. What is the most appropriate approach?
Treat it as the information systems department's own decision to accept the risk, and have the leader process it as corrected
Ask the audit department to withdraw this finding for now, and arrange for it to be raised again with the same content next fiscal year once budget is available
Since nothing can be done without budget, keep extending the corrective deadline and report the status as "in progress"
Organize the anticipated impact if tracing remains impossible, the resources required, and who would accept the risk if the response is deferred, then escalate to management for a decision
AnswerD. Organize the anticipated impact if tracing remains impossible, the resources required, and who would accept the risk if the response is deferred, then escalate to management for a decision
A correction that requires budget and cooperation from other departments cannot be decided at the discretion of a single staff member or department. The correct approach is to organize the anticipated impact, the resources needed, and who would accept the risk if deferred, and escalate to management for a decision. Repeatedly extending the deadline while reporting "in progress" amounts to leaving it unaddressed in substance, and requesting withdrawal of the finding erases the facts. Risk acceptance must be an explicit decision made by someone in a position of responsibility, not something a staff member can simply process as corrected.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original