セキュリティ インシデント プロセスを確認する IS 監査人は、インシデントは解決され終了しているものの、根本原因が調査されていないことに気付きました。この状況で最も重要な懸念事項は次のどれですか。
正解:C
The major concern with the situation where security incidents are resolved and closed, but root causes are not investigated, is that vulnerabilities have not been properly addressed. Vulnerabilities are weaknesses or gaps in the security posture of an organization that can be exploited by threat actors to compromise its systems, data, or operations. If root causes are not investigated, vulnerabilities may remain undetected or unresolved, allowing attackers to exploit them again or use them asentry points for further attacks. This can result in repeated or escalated security incidents that can cause more damage or disruption to the organization.
The other options are not as major as the concern about vulnerabilities, but rather secondary or related issues that may arise from the lack of root cause analysis. Abuses by employees have not been reported is a concern that may indicate a lack of awareness, accountability, or monitoring of insider threats. Lessons learned have not been properly documented is a concern that may indicate a lack of improvement, learning, or feedback from security incidents. Security incident policies are out of date is a concern that may indicate a lack of alignment, review, or update of security incident processes.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 254
* Why Root Cause Analysis is Crucial to Incident Response (IR) - Avertium3
* Root Cause Analysis Steps and How it Helps Incident Response ...