ある組織が最近、多数のパートタイム従業員を雇用しました。年次監査中に、パートタイム従業員が使用する多くのユーザー ID とパスワードが手順マニュアルに記載されていることが判明しました。この状況を最もよく表しているのはどれですか。
正解:C
Documenting user IDs and passwords in procedure manuals is a vulnerability that exposes the organization to unauthorized access, data breaches, and other security risks. A vulnerability is a weakness or flaw in a system, process, or control that can be exploited by a threat. A threat is a potential cause of an unwanted incident that may harm the system or organization. A risk is the combination of the likelihood and impact of a threat exploiting a vulnerability. A policy violation is an act of non-compliance with a rule or standard that is established by the organization. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 8; CRISC Review Manual, 6th Edition, page 67.