The organisation which you work for has been functioning without an Information Technology Auditor all these past years. When they discovered that you were recently awarded with the prestigious Certified Information Systems Auditor [CISA], they took this as an opportunity to expand the Information Management & Security faculty of the business organisation and offered you the position of Information Systems & Security Auditor. Your role among other things is to ensure that the organisation’s systems and all IT Infrastructure comply with all known global Information Systems and Security Standards. As a security measure, the organisation requires you to ensure that its Information Systems infrastructure, procedures and processes comply, and are properly registered with International Standards organisations like the ISO, among others. The business intends to always ensure that all systems and infrastructure are well protected and have acquired a high level of resilience in the event of a cyberattack of any kind or any act of fraud that may be attempted on the organisation as a prime target either by internal or external perpetrators. QUESTION 1.4 Identify and expand on the FOUR (4) approaches that are recognised by ISO 13335 in identifying and mitigating risks to the organisation’s IT infrastructure.

icon
Related questions
Question

The organisation which you work for has been functioning without an Information Technology Auditor all these past years.
When they discovered that you were recently awarded with the prestigious Certified Information Systems Auditor [CISA], they took this as an opportunity to expand the Information Management & Security faculty of the business organisation and offered you the position of Information Systems & Security Auditor. Your role among other things is to ensure that the organisation’s systems and all IT Infrastructure comply with all known global Information Systems and Security Standards.
As a security measure, the organisation requires you to ensure that its Information Systems infrastructure, procedures and processes comply, and are properly registered with International Standards organisations like the ISO, among others. The business intends to always ensure that all systems and infrastructure are well protected and have acquired a high level of resilience in the event of a cyberattack of any kind or any act of fraud that may be attempted on the organisation as a prime target either by internal or external perpetrators.

QUESTION 1.4

Identify and expand on the FOUR (4) approaches that are recognised by ISO 13335 in identifying and mitigating risks to the organisation’s IT infrastructure.

 

Expert Solution
steps

Step by step

Solved in 3 steps

Blurred answer