IS 監査人は、製造工場の産業用 IoT (モノのインターネット) インフラストラクチャの実装に関連する制御のレビューを準備しています。次の脆弱性のうち、組織にとって最大のセキュリティ リスクとなるものはどれですか。
正解:B
The use of open-source software components in IoT devices presents the greatest security risk due to potential vulnerabilities that may exist within the software. These vulnerabilities can be exploited if patches are not applied promptly, and the organization might not have direct control over the software's maintenance and security updates. This risk is amplified in critical manufacturing environments where compromised IoT devices can lead to operational disruptions. * Physical Security (Option A):While important, theft of IoT devices generally poses less risk compared to a system-wide compromise due to software vulnerabilities. * Firmware Storage Constraints (Option C):While a limitation, this is a secondary concern compared to exploitable software. * Devices Not Using Wireless Connectivity (Option D):Wired devices are generally more secure, reducing this as a significant concern. Reference:ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.