
100%更新されたのはISACA CRISC日本語限定版PDF問題集
有効な試験問題を試そうCRISC日本語には無料サイトで限定お試しチャンス
質問 # 394
リスク評価の最初のステップは次のどれですか?
- A. 固有のリスクの特定
- B. リスク要因を特定する
- C. 資産識別
- D. リスクガバナンスの見直し
正解:C
解説:
リスク評価の最初のステップは資産の特定です。これは、人材、情報、システム、プロセス、インフラストラクチャなど、組織にとって関連性があり価値のある資産を特定して文書化するプロセスです1。資産の特定は、次のことに役立ちます。
* リスク評価の範囲と境界を確立し、範囲内のすべての資産が考慮され、カバーされていることを確認します2。
* 資産の重要度と優先度を決定し、組織の目標に対する重要性と貢献度に基づいて適切な値または評価を割り当てます3。
* 資産に影響を及ぼす可能性のある潜在的な脅威と脆弱性を特定し、その発生可能性と資産への影響を評価します4。
その他のオプションは、次の理由により、リスク評価の最初のステップではありません。
* リスク ガバナンスの見直しは、リスク評価の最初のステップではなく、リスク評価の前提条件または基礎です。リスク ガバナンスは、組織のリスク管理活動とイニシアチブを導き、監督する原則、ポリシー、役割、責任のシステムです5。リスク ガバナンスを見直すことで、リスク評価が組織のリスク戦略、文化、リスク許容度と一致し、リスク評価プロセスが一貫性があり、効果的で、効率的であることを保証できます6。
* リスク要因の特定は最初のステップではなく、資産特定の後続または並行ステップです。リスク要因とは、リスク イベントの発生または結果に影響を及ぼしたり、その一因となったりする要素または条件です7。リスク要因を特定することで、リスクの原因と発生源を理解し、その発生確率と重大度に基づいてリスクを分析および評価することができます。
* 固有リスクの特定は最初のステップではなく、資産の特定とリスク要因の特定の後のステップ、またはそれに依存するステップです。固有リスクとは、リスク対応を実施する前に存在するリスクのレベルです。固有リスクを特定することで、資産の露出度または不確実性を測定し、リスク対応の必要性と範囲を判断するのに役立ちます。
参考文献 =
* リスクガバナンス - CIO Wiki
* リスクガバナンスフレームワーク - CIO Wiki
* 資産識別 - CIO Wiki
* 資産の識別と評価 - ISACA
* 資産の重要性 - CIO Wiki
* 脅威と脆弱性の評価 - CIO Wiki
* リスク要因 - CIO Wiki
* [リスク要因分析 - CIO Wiki]
* [固有のリスク - CIO Wiki]
* [固有のリスク評価 - CIO Wiki]
* [リスク評価 - CIO Wiki]
質問 # 395
あるグローバル組織は、災害発生時に顧客情報システムを海外のクラウド サービス プロバイダーに移管することを検討しています。次のうち、最も重要なリスク考慮事項はどれですか。
- A. 国境を越えたデータ転送に関する規制上の制限
- B. 各企業内の経営慣行
- C. ベンダー契約におけるサービスレベル目標
- D. 各国の組織文化の違い
正解:A
解説:
Regulatory restrictions for cross-border data transfer can significantly impact compliance, making this the most critical consideration. Addressing such restrictions ensures adherence toLegal and Regulatory Requirementsin risk management.
質問 # 396
効果的な IT セキュリティ意識向上プログラムの最も優れた指標は次のどれですか?
- A. 内部フィッシングテストの成功率の低下
- B. セキュリティ違反に対する懲戒処分の数
- C. 報告されたセキュリティインシデントの数が減少しました
- D. セキュリティトレーニングを完了した従業員の数
正解:A
解説:
The best indicator of an effective IT security awareness program is the decreased success rate of internal phishing tests. Phishing is a type of social engineering attack that attempts to trick the users into revealing their personal or confidential information, or clicking on malicious links or attachments, by impersonating a legitimate entity or person. Internal phishing tests are simulated phishing attacks that are conducted by the enterprise to test the awareness and behavior of the employees in response to phishing emails. A decreased success rate of internal phishing tests means that fewer employees fall victim to the phishing attempts, and that they are more aware and vigilant of the phishing threats and techniques. A decreased success rate of internal phishing tests also implies that the IT security awareness program has effectively educated and trained the employees on how to recognize and report phishing emails, and how to protect themselves and the enterprise from phishing attacks. A decreased number of reported security incidents, a number of disciplinary actions issued for security violations, and a number of employees that complete security training are not as good indicators of an effective IT security awareness program as a decreased success rate of internal phishing tests, as they do not directly measure the awareness and behavior of the employees in relation to phishing, and may be influenced by other factors such as reporting mechanisms, enforcement policies, and training availability. References = CRISC Review Manual, 6th Edition, ISACA, 2015, page 220.
質問 # 397
リスク管理の最新情報を経営幹部と共有する際に最も重要な考慮事項は次のどれですか?
- A. 組織リスクの集約ビューの使用
- B. 組織の目標との関連性を確保する
- C. 主要リスク指標(KRI)データに依存
- D. リスク指標の傾向分析
正解:B
解説:
CRISC レビュー マニュアル (デジタル版) によると、リスク管理の最新情報を経営幹部と共有する際に最も重要な考慮事項は、組織の目標との関連性を確保することです。これにより、リスク管理をビジネス戦略およびパフォーマンスと一致させることができます。リスク管理の最新情報は、次の点を満たす必要があります。
* 組織の目標と目的の達成に影響を与える可能性のある主要なリスクを強調する
* 意思決定をサポートし、ビジネスの回復力を高める上でのリスク管理の価値と利点を実証する
* 組織の現在のリスクプロファイル、リスク選好度、リスク許容度、リスクエクスポージャーに関する明確かつ簡潔な情報を提供する
* 特定されたリスクに対処するために適切なリスク対応策とリソースの割り当てを推奨する
* リスク管理の監督と統制における経営幹部の役割と責任を伝える 参考文献 = CRISC レビューマニュアル (デジタル版)、第 4 章: IT リスクの監視と報告、セクション 4.2: IT リスク報告、221-2221 ページ
質問 # 398
リスク管理担当者は、プラットフォームによって付加される価値と組織のリスク許容度に基づいて、サードパーティのブロックチェーン統合プラットフォームの導入を評価するよう求められています。リスク管理担当者にとって最善の行動方針は次のどれですか?
- A. 標準および規制に関連するリスクを確認します。
- B. プロセスの変更に合わせてリスク レジスタを更新します。
- C. 利害関係者とともにリスク評価を実施します。
- D. サードパーティの耐障害性テストを実施します。
正解:C
解説:
ステークホルダーとのリスク評価は、リスク担当者が組織の目標、リスク選好度、リスク許容度に関連してサードパーティのブロックチェーン統合プラットフォームの価値とリスクを評価するのに役立つため、最善の行動方針です。リスク評価は、プラットフォームに関連するリスクと機会を特定して優先順位を付け、適切なリスク対応と管理を開発するのにも役立ちます。
参考資料: 回答は以下の情報源に基づいています。
*CRISC レビューマニュアル、第 7 版、第 2 章: IT リスク評価、75-761 ページ
*CRISC レビュー問題、解答、解説データベース、12 か月サブスクリプション、質問 ID: QID-
10012
質問 # 399
ビジネス影響分析 (BIA) を実施する際の最初のステップは次のどれですか?
- A. 業務継続性に影響を与えるイベントの特定
- B. データ分類スキームの作成
- C. 過去のリスク評価結果の分析
- D. 重要な情報資産の特定
正解:D
解説:
The first step in conducting a BIA is to identify critical information assets. This involves determining which assets are essential to the organization's operations and would have the most significant impact if disrupted.
Understanding these assets sets the foundation for assessing potential impacts and developing appropriate recovery strategies.
Reference:ISACA CRISC Review Manual, 7th Edition, Chapter 2: IT Risk Assessment, Section: Business Impact Analysis.
質問 # 400
顧客データの損失に関連するリスクの概要を提供するのに最も役立つ役割は次のどれですか?
- A. 顧客データベース管理者
- B. 顧客データ管理者
- C. 監査委員会
- D. データプライバシー担当者
正解:D
解説:
データ プライバシー オフィサーは、顧客データの収集、処理、保管、開示に関する適用法、規制、標準に組織が準拠していることを確認する役割です1。データ プライバシー オフィサーは、顧客データのプライバシーとセキュリティを保護し、顧客データの損失のリスクを防止または軽減するためのポリシー、手順、および制御を開発して実装する責任も負います2。データ プライバシー オフィサーは、顧客データの損失に関連するリスクの概要を提供するのに最も役立つ役割です。その理由は次のとおりです。
* データプライバシー担当者は、顧客データ保護に関する法的および倫理的要件とベストプラクティスに関する知識と専門知識を持ち、顧客データを危険にさらす可能性のある潜在的な脅威と脆弱性を特定して評価することができます3。
* データプライバシー担当者は、顧客データのライフサイクルを監督および監視し、組織がデータの最小化、目的の制限、正確性、完全性、機密性、説明責任の原則に従っていることを確認する権限と責任を持ちます4。
* データプライバシー担当者は、顧客データのリスクプロファイルについて経営陣やその他の関係者に報告および助言し、適切なリスク対応と改善措置を推奨して実施するための可視性とコミュニケーションスキルを備えています5。
その他のオプションは、顧客データの損失に関連するリスクの概要を提供するのに最も役立つ役割ではありません。その理由は次のとおりです。
* 顧客データベース マネージャーは、顧客データを保存および管理するデータベース システムの設計、開発、保守、最適化を担当する役割です6。顧客データベース マネージャーは、顧客データを不正アクセス、変更、削除から保護するための技術的なスキルと知識を持っている場合がありますが、組織レベルや規制レベルではなくデータベース レベルのみに焦点を当てているため、顧客データのリスクを包括的または全体的に把握していない可能性があります。
* 顧客データ管理者は、データ所有者の指示と許可に従って顧客データを取り扱い、処理し、保管する役割です7。顧客データ管理者は、顧客データを偶発的または意図的な損失、損傷、または漏洩から保護するための運用上の義務と責任を負う場合がありますが、リスク管理の原則と実践ではなく、事前に定義されたルールと手順のみに従う可能性があるため、顧客データのリスクに対する戦略的または分析的な視点を持っていない可能性があります。
* 監査委員会は、組織の財務報告、内部統制、監査機能を監督および評価する責任を負う独立した取締役またはメンバーのグループです。監査委員会は、顧客データ保護に関する組織のコンプライアンスとパフォーマンスをレビューおよび検証するための監督および保証の役割と責任を負う場合がありますが、リスク評価と分析ではなく監査レポートと調査結果のみに依存する可能性があるため、顧客データのリスクを直接的または積極的に把握できない場合があります。
参考文献 =
* データプライバシー責任者 - CIO Wiki
* データ保護責任者 (DPO) とは何ですか? - Techopedia の定義
* データプライバシー責任者: 役割と責任 - ISACA
* データ保護原則 - CIO Wiki
* データ プライバシー オフィサー: なる方法と必要な理由 - ISACA
* データベース マネージャー - CIO Wiki
* データ管理者 - CIO Wiki
* [監査委員会 - CIO Wiki]
質問 # 401
リスク管理担当者が、組織の災害復旧 (DR) 機能に関するレポートの作成を支援しています。全体的な復旧プロファイルに最も影響を与える情報はどれでしょうか。
- A. 復旧計画を必要とするシステムの数が増加しました。
- B. リカバリ目標時間が長いシステムの割合が減少しました。
- C. 過去 1 年間にテストされたシステムの数が増加しました。
- D. 回復目標時間を満たすシステムの割合が増加しました。
正解:B
解説:
According to the CRISC Review Manual (Digital Version), the percentage of systems with long recovery target times has decreased is the information that would have the most impact on the overall recovery profile, as it indicates that the organization has improved its ability to restore its critical systems and processes within the acceptable time frames after a disaster. The recovery target time, also known as the recovery time objective (RTO), is the maximum acceptable time that an application, computer, network, or system can be down after an unexpected disaster, failure, or comparable event takes place. The recovery profile, also known as the recovery point objective (RPO), is the maximum acceptable amount of data loss measured in time. A lower percentage of systems with long recovery target times means that the organization has:
Reduced the gap between the business requirements and the IT capabilities for disaster recovery Enhanced the resilience and availability of its critical systems and processes Minimized the potential losses and damages caused by prolonged downtime Increased the confidence and satisfaction of its stakeholders and customers References = CRISC Review Manual (Digital Version), Chapter 3: IT Risk Response, Section 3.3: Risk Response Options, pp. 174-1751
質問 # 402
主要リスク指標 (KRI) の選択に利害関係者を関与させることの主な利点は次のどれですか?
- A. リスク処理の決定を最適化する
- B. 既存の指標を活用する
- C. リスク認識の向上
- D. リスク所有者からの賛同を得る
正解:C
解説:
The main benefit of involving stakeholders in the selection of key risk indicators (KRIs) is improving risk awareness, as it helps to communicate the risk exposure, appetite, and tolerance of the organization to the relevant parties. KRIs are metrics that provide information on the level of exposure to a given operational risk1. By involving stakeholders in the selection of KRIs, the risk practitioner can ensure that the KRIs are aligned with the stakeholder expectations, needs, and objectives, and that they reflect the most significant risks that affect the organization. This also helps to foster a risk culture and a shared understanding of risk among the stakeholders, which can enhance the risk management process and performance. The other options are not the main benefit of involving stakeholders in the selection of KRIs, although they may be some of the outcomes or advantages of doing so. Obtaining buy-in from risk owners, leveraging existing metrics, and optimizing risk treatment decisions are all important aspects of risk management, but they are not the primary reason for involving stakeholders in the selection of KRIs. References = Key Risk Indicators; Key Risk Indicators: A Practical Guide; The 10 Types of Stakeholders That You Meet in Business; What are Stakeholders? Stakeholder Definition | ASQ
質問 # 403
ウイルス対策プログラムの有効性を測定するための最適な主要業績評価指標 (KPI) は次のどれですか?
- A. 一定期間内に検出された誤検知の数
- B. 最新のマルウェア定義が適用されている IT 資産の割合
- C. ウイルス対策ソフトウェアによって生成されたアラートの数
- D. ウイルス対策ソフトウェアの更新頻度
正解:B
解説:
ウイルス対策プログラムは、コンピュータ、サーバー、ネットワークなどの IT 資産からウイルス、ワーム、ランサムウェアなどの悪意のあるソフトウェアを検出して削除するソフトウェアです。ウイルス対策プログラムの有効性は、プログラム目標の達成度と企業のリスク選好度およびリスク許容度との整合性を反映する主要業績評価指標 (KPI) によって測定できます。ウイルス対策プログラムの有効性を測定するのに最適な KPI は、最新のマルウェア定義が適用されている IT 資産の割合です。マルウェア定義とは、既知の悪意のあるソフトウェアのシグネチャまたはパターンを含むファイルまたはデータベースであり、ウイルス対策プログラムがマルウェアをスキャンして識別するために使用されます。最新のマルウェア定義が適用されている IT 資産の割合は、ウイルス対策プログラムが最新の脅威または新たな脅威から IT 資産をどの程度保護し、マルウェアに関連するリスクの露出と影響を軽減できるかを示します。その他のオプションは、保護の品質や適時性、または企業のリスク選好度やリスク許容度との整合性を反映していない可能性があるため、最新のマルウェア定義が適用されている IT 資産の割合ほど適切ではありません。参考文献 = リスクおよび情報システム制御研究マニュアル、第 7 版、第 4 章、セクション 4.3.2.1、171 ~ 172 ページ。
質問 # 404
予定外のパッチ適用を最も効果的に防ぐには、次のどれがよいでしょうか?
- A. 補正コントロール
- B. ネットワークベースのアクセス制御
- C. 変更管理
- D. 職務の分離
正解:C
解説:
Change management is the best way to prevent an unscheduled application of a patch, because it ensures that any changes to the IT environment are planned, approved, tested, and documented. Change management is a process that controls the implementation of changes to IT systems, applications, infrastructure, or processes. It aims to minimize the risk of disruption, errors, or failures caused by changes. Applying a patch is a type of change that may affect the security, functionality, or performance of an IT system or application. Therefore, applying a patch should follow the change management process and schedule, and avoid any unscheduled or unauthorized patching. Network-based access controls, compensating controls, and segregation of duties are all useful controls to protect the IT environment from unauthorized or malicious access, but they do not prevent an unscheduled application of a patch, as they do not address the change management process.
References = Risk and Information Systems Control Study Manual, Chapter 5, Section 5.4.2, page 211
質問 # 405
個人のデバイスに保存されている会社のデータの損失に関連するリスクを軽減するために、最も効果的なのは次のどれですか?
- A. 個人用デバイスの許容使用ポリシー
- B. セキュリティ意識向上トレーニングとテスト
- C. データを同期する前にユーザーのログオンが必要
- D. 強制認証とデータ暗号化
正解:D
解説:
個人のデバイスに保存されている企業データの損失に伴うリスクは、データが権限のない第三者によってアクセス、開示、または変更され、機密性、整合性、または可用性の侵害につながる可能性があることです1。
このリスクを軽減する最も効果的な方法は、企業データを保存している個人用デバイスで認証とデータ暗号化を実施することです。認証とは、データにアクセスしているユーザーまたはデバイスの ID を確認し、パスワード、コード、生体認証要素、またはこれらの組み合わせを要求することで不正アクセスを防止するプロセスです2。データ暗号化とは、データを読み取り不可能な形式に変換する技術で、データを復号化して元の形式に復元するにはキーが必要です3。個人用デバイスで認証とデータ暗号化を実施することで、組織は、許可されたユーザーまたはデバイスのみが企業データにアクセスできるようにし、デバイスが紛失または盗難にあった場合でも、データが不正な開示や変更から保護されるようにすることができます4。個人用デバイスの使用規定、データの同期前のユーザー ログオンの要求、セキュリティ意識のトレーニングとテストは、認証とデータ暗号化と同じレベルの保護を提供しないため、個人用デバイスに保存されている企業データの損失に関連するリスクを軽減する最も効果的な方法ではありません。個人用デバイスの許容使用ポリシーとは、個人用デバイスを業務目的で使用する際のルールとガイドラインを定義する文書です。これには、許可されるデバイス、データ、アプリケーションの種類、必要なセキュリティ対策、ユーザーと組織の責任と賠償責任などが含まれます5。個人用デバイスの許容使用ポリシーは、個人用デバイスの使用に関する共通の理解と期待を確立するのに役立ちますが、セキュリティ対策のコンプライアンスや有効性を強制または保証するものではありません。データの同期前にユーザーのログオンを要求するとは、個人用デバイスと会社のネットワークまたはシステム間でデータを転送または更新する前に、ユーザーに資格情報の入力を要求する手法です6。データの同期前にユーザーのログオンを要求すると、データの不正な同期を防ぐのに役立ちますが、個人用デバイスにすでに保存されているデータは保護されません。セキュリティ意識向上トレーニングとテストは、強力なパスワードの使用、ソフトウェアの更新、フィッシングメールの回避、インシデントの報告の重要性など、個人用デバイスを業務目的で使用する際のセキュリティリスクとベストプラクティスについてユーザーを教育し、評価するプロセスです7。セキュリティ意識のトレーニングとテストは、ユーザーの知識と行動を向上させるのに役立ちますが、セキュリティ対策の実装やパフォーマンスを保証または監視することはできません。参考資料 = 1: BYOD セキュリティ: リスクとは何か、またそのリスクを軽減するにはどうすればよいか?
2: 多要素認証 (MFA) とは何ですか? | Duo Security3: [データ暗号化とは何ですか? | 定義と FAQ] 4: 職場で個人デバイスを使用するリスクを軽減する方法5: BYOD ポリシー テンプレート - 無料サンプルを入手6: 携帯電話を Windows 10 と同期する方法 | PCMag7: セキュリティ意識向上トレーニング:
それは何であり、なぜ重要なのでしょうか?
質問 # 406
ある組織がITセキュリティポリシーを改訂しています。ポリシーが確実に遵守されるようにするために、最初に行うべきことは次のうちどれですか?
- A. 業界の同業他社と比較して、ポリシーをベンチマークします。
- B. 政策の周知と啓発戦略を策定する。
- C. 旧政策と新政策のギャップ分析を実行します。
- D. ポリシー違反を監視するための技術的な制御を実装します。
正解:B
解説:
The correct answer isAbecause the first thing that should be done to help ensure a revised IT security policy is followed is todevelop a policy socialization and awareness strategy. A policy cannot be followed consistently unless employees and stakeholders understand it, know their responsibilities, and are aware of expected and prohibited behaviors.
The other options are less appropriate as the first step for adoption:
* B. Implement technical controls to monitor for policy violationsmay support enforcement later, but awareness must come first.
* C. Benchmark the policy against industry peersmay improve policy quality, but it does not ensure internal compliance.
* D. Perform a gap analysis of the old and new policymay help assess changes, but it does not directly ensure people will follow the revised policy.
Exact Extracts supporting the answer:
* "To make a BYOD policy effective the most enabling approach is educating users on acceptable and unacceptable practices."
* "The best proactive approach for practicing professional ethics within an enterprise is to provide ethics awareness training."
* "The most effective way to support adherence to an enterprise ' s code of ethics is by ensuring periodic training evaluation and attestation of employees."
* "When developing an IT risk awareness program the primary consideration is how technology risk can affect each attendee's area of business."
* "The BEST approach when conducting an IT risk awareness campaign is to provide common messages tailored for different groups." These extracts support that awareness and communication are the most effective first actions to encourage adherence to a revised policy.
質問 # 407
ある組織は、クレジットカードによる支払いを受け付けられるようにシステムを変更することを検討しています。データ漏洩のリスクを軽減するために、組織が最初に行うべきことは何でしょうか?
- A. リスクレジスタを更新します。
- B. 追加のコントロールを実装します。
- C. セキュリティ戦略を更新します。
- D. リスク評価を実施します。
正解:D
解説:
組織がシステムを変更してクレジットカード決済の受け入れを可能にする際に、データ漏洩のリスクを軽減するために最初に行うべきことは、リスク評価を実施することです。これは、システムとデータに影響を及ぼす可能性のある潜在的なリスク、脅威、脆弱性、およびそれらがビジネス目標とプロセスに及ぼす可能性と影響を特定して分析するプロセスだからです。リスク評価は、現在のリスク レベルとリスクの露出度を判断し、適切なリスク対応と制御を選択して実装するための基礎を提供するのに役立ちます。その他のオプションは、組織が最初に行うべきことではありません。その理由は次のとおりです。
* オプション B: セキュリティ戦略の更新はリスク評価の実施の結果ですが、組織が最初に行うべきことではありません。セキュリティ戦略は、システムとデータのセキュリティ目標、ポリシー、標準、手順を定義する計画であり、リスク評価の結果とビジネス要件および期待に一致している必要があります。
* オプション C: 追加のコントロールを実装することは、リスク評価の結果に対する対応ですが、組織が最初に行うべきことではありません。コントロールとは、リスク、脅威、脆弱性の発生や影響を防止または軽減し、システムとデータの機密性、整合性、可用性を確保するために設計および実装される対策です。
* オプション D: リスク レジスタの更新はリスク評価プロセスの一部ですが、組織が最初に行うべきことではありません。リスク レジスタは、特定されたリスク、その特性、ステータス、および対応を文書化して追跡するツールであり、システムとデータの現在のリスク プロファイルとエクスポージャーを反映するために定期的に更新する必要があります。参考文献 = リスクおよび情報システム制御研究マニュアル、第 7 版、ISACA、2020 年、p. 108。
質問 # 408
リスクシナリオを開発する際に最も重要なのは次のどれですか?
- A. IT監査との連携
- B. 脆弱性評価の実施
- C. 主要な利害関係者からの意見の収集
- D. ビジネス影響分析 (BIA) のレビュー
正解:C
解説:
リスク シナリオを作成する際に最も重要な要素は、主要な利害関係者から意見を得ることです。リスク シナリオとは、企業の目標、プロセス、またはリソースに影響を及ぼす可能性のあるイベントまたは状況の説明です。ビジネス オーナー、プロセス オーナー、主題専門家、外部関係者などの主要な利害関係者から意見を得ることで、リスク シナリオが現実的で、関連性があり、包括的なものになります。また、リスク シナリオのソース、要因、指標、可能性、影響、および対応を特定し、企業のリスク選好度とリスク許容度に合わせるのにも役立ちます。主要な利害関係者から意見を得ることで、リスク管理に対する協力的かつ参加型のアプローチが促進され、利害関係者のリスク認識と所有権が強化されます。参考文献 = リスクおよび情報システム管理研究マニュアル、第 7 版、第 2 章、セクション 2.1.3、621 ページ
質問 # 409
ある組織が給与計算機能を外部サービス プロバイダーにアウトソーシングすることを計画しています。プロバイダーを選択する際に最も重要な考慮事項は次のどれですか。
- A. 主要業績評価指標 (KPI) の透明性
- B. システムの災害復旧計画 (DRP)
- C. プロバイダーを監査する権利
- D. データのプライバシーを確保するための内部管理
正解:D
解説:
給与計算業務をアウトソーシングする外部サービス プロバイダーを選択する際に最も重要な考慮事項は、データ プライバシーを確保するための内部管理です。給与計算業務には、給与、税金、福利厚生、銀行口座など、従業員の機密性の高い個人情報や財務情報を処理および保存することが含まれます。この情報は、組織や従業員に法的、規制的、評判的、または財務的な影響を及ぼす可能性があるため、不正アクセス、開示、変更、または紛失から保護する必要があります。
したがって、外部サービス プロバイダーは、データのプライバシーと組織のポリシーおよび標準への準拠を確保するために、暗号化、アクセス制御、バックアップ、ログ記録、監視などの適切な内部管理を備えている必要があります。災害復旧計画、監査権、KPI の透明性も、外部サービス プロバイダーを選択する際の重要な考慮事項ですが、データのプライバシーを確保するための内部管理ほど重要ではありません。参考文献 = リスクおよび情報システム管理研究マニュアル、第 7 版、第 5 章、セクション 5.2.1.2、ページ 2461
1: ISACA リスクおよび情報システム管理認定 (CRISC) 試験ガイド、質問への回答
648.
質問 # 410
データの誤分類に関連する最大のリスクは次のどれですか?
- A. 不正アクセス
- B. データの中断
- C. 不適切な保存スケジュール
- D. リソース割り当てが不十分
正解:A
解説:
According to the CRISC Review Manual, the greatest risk associated with the misclassification of data is unauthorized access, because it can result in the loss of confidentiality, integrity, and availability of the data.
Data classification is the process of assigning categories to data based on its sensitivity and value to the organization. Data classification helps to determine the appropriate level of protection and handling for the data. If the data is misclassified, it may not receive the adequate level of security controls, and it may be accessed by unauthorized or inappropriate users. The other options are not the greatest risks associated with the misclassification of data, as they are less likely or less severe than unauthorized access. Inadequate resource allocation is the risk of not allocating sufficient resources to protect the data, which may affect its availability and performance. Data disruption is the risk of losing or corrupting the data, which may affect its integrity and availability. Inadequate retention schedules is the risk of not retaining the data for the required period of time, which may affect its compliance and usability. References = CRISC Review Manual, 7th Edition, Chapter 4, Section 4.1.1, page 161.
質問 # 411
組織がクラウド コンピューティング戦略の導入を計画している場合、リスク担当者が最初に行うべき行動は次のどれですか。
- A. 脅威分析を実施します。
- B. クラウド コンピューティング ポリシーを作成します。
- C. コントロール評価を実行します。
- D. 実装のための予算を要求する
正解:C
解説:
The first course of action for a risk practitioner when an organization plans to adopt a cloud computing strategy is to perform a controls assessment. This means evaluating the existing controls in the organization and the cloud service provider, and identifying the gaps and weaknesses that need to be addressed. A controls assessment can help to determine the level of risk exposure and the suitability of the cloud service model and provider for the organization's needs and objectives. It can also help to establish the baseline for monitoring and reporting on the cloud service performance and compliance. References = Risk and Information Systems Control Study Manual, Chapter 5, Section 5.3.2.2, p. 242-243
質問 # 412
組織の初期のリスク シナリオ セットを開発するときに、最初に実行する必要があるのは次のうちどれですか。
- A. 関連するビジネス活動を考慮します。
- B. ボトムアップアプローチを使用します。
- C. トップダウンアプローチを使用します。
- D. 業界標準のシナリオを参照してください。
正解:A
質問 # 413
新しく設立された企業は、情報資産を保護する必要があります。ガバナンスの観点から、最初に行うべきことは何ですか?
- A. 情報保持要件とポリシーを定義する
- B. セキュリティ管理プロセスと手順を確立する
- C. 情報資産のインベントリを確立する
- D. 情報セキュリティ意識向上トレーニングを提供する
正解:C
解説:
The first thing that should be done from a governance perspective to secure the information assets of a newly incorporated enterprise is to establish an inventory of information assets. An inventory of information assets is a document that lists and categorizes all the information assets that the organization owns, uses, or manages, such as data, documents, systems, applications, and devices. An inventory of information assets helps to identify and classify the information assets based on their value, sensitivity, and criticality, and to determine the appropriate level of protection and control for each asset. An inventory of information assets also helps to support the development and implementation of other information security activities, such as risk assessment, policy formulation, awareness training, and incident response. The other options are not the first thing that should be done, although they may be important steps or components of the information security governance.
Defining information retention requirements and policies, providing information security awareness training, and establishing security management processes and procedures are all activities that can help to secure the information assets, but they require the prior knowledge and understanding of the information assets. References = Risk and Information Systems Control Study Manual, Chapter 3, Section 3.1.1, page 3-3.
質問 # 414
十分に開発された、データに基づくリスク測定は、次のようなものである必要があります。
- A. データが収集された当日に経営陣に報告されます。
- B. 将来を見据えた視点を提供することに重点を置いています。
- C. 運用中の本番システムから直接取得されたデータ フィード。
- D. 組織の最下位レベルを反映します。
正解:B
解説:
十分に開発されたデータ駆動型リスク測定は、将来を見据えた見解を提供することに重点を置く必要があります。これにより、組織はリスク レベルとエクスポージャーの潜在的な変化と影響を予測して準備し、リスクに対処するために積極的かつ適切な措置を講じることができます。その他のオプションは、十分に開発されたデータ駆動型リスク測定の特性ではありません。リスク測定の戦略的、包括的、またはタイムリーな側面をそれぞれ反映していない可能性があるためです。参考文献 = CRISC レビュー マニュアル、第 7 版、110 ページ。
質問 # 415
企業がリスク許容度を定義し、伝達するのに最も役立つのは次のどれですか?
- A. リスクレジスター
- B. ヒートマップ
- C. ギャップ分析
- D. リスク評価
正解:A
解説:
The best way to help an enterprise define and communicate its risk appetite is to use a risk register, which is a document that records and summarizes the key information and data about the identified risks and the risk responses1. A risk register can help to:
Define the risk appetite, which is the amount and type of risk that the enterprise is willing to accept or pursue in order to achieve its objectives2. The risk register can include the risk appetite statement, which is a clear and concise expression of the enterprise's risk preferences and boundaries3.
Communicate the risk appetite, which is the process of sharing and informing the risk appetite to the relevant stakeholders, such as the board, the management, the employees, or the customers4. The risk register can be used as a communication tool, which can provide a consistent and transparent view of the enterprise's risk profile and performance5.
The other options are not the best ways to help an enterprise define and communicate its risk appetite, because:
Gap analysis is a technique that compares the current state and the desired state of a process, system, or organization, and identifies the gaps or differences between them6. Gap analysis can help to assess the alignment or misalignment of the enterprise's risk appetite with its risk level, but it does not help to define or communicate the risk appetite itself.
Risk assessment is a process that estimates the probability and impact of the risks, and prioritizes the risks based on their significance and urgency. Risk assessment can help to identify and analyze the risks that may affect the enterprise's objectives, but it does not help to define or communicate the risk appetite itself.
Heat map is a graphical representation that uses colors to indicate the level or intensity of a variable, such as risk. Heat map can help to visualize and compare the risks based on their probability and impact, but it does not help to define or communicate the risk appetite itself.
References =
Risk Register - CIO Wiki
Risk Appetite - CIO Wiki
Risk Appetite Statement - CIO Wiki
Risk Communication - CIO Wiki
Risk Reporting - CIO Wiki
Gap Analysis - CIO Wiki
[Risk Assessment - CIO Wiki]
[Heat Map - CIO Wiki]
[Risk and Information Systems Control documents and learning resources by ISACA]
質問 # 416
......
ISACA CRISC日本語公式認定ガイドPDF:https://jp.fast2test.com/CRISC-JPN-premium-file.html