IS 監査人は、ネットワーク セキュリティ レビューの現場調査フェーズを完了し、初期段階の次の調査結果を準備していますが、最も高いリスクとしてランク付けする必要がありますか?
正解:A
The finding that should be ranked as the highest risk is that network penetration tests are not performed.
Network penetration tests are simulated cyberattacks that aim to identify and exploit the vulnerabilities and weaknesses of the network security controls, such as firewalls, routers, switches, servers, and devices.
Network penetration tests are essential for assessing the effectiveness and resilience of the network security posture, and for providing recommendations for improvement and remediation. If network penetration tests are not performed, the organization may not be aware of the existing or potential threats and risks to its network, and may not be able to prevent or respond to real cyberattacks, which can result in data breaches, service disruptions, financial losses, reputational damage, and legal or regulatory penalties. The other findings are also important, butnot as risky as the lack of network penetration tests, because they either do not directly affect the networksecurity controls, or they can be addressed by documentation or approval processes.
References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4