シナリオ5 CyberShielding Systems Inc.は、情報技術インフラ全体にわたるセキュリティサービスを提供しています。エンドポイントセキュリティ、ファイアウォール、ウイルス対策ソフトウェアなど、サイバーセキュリティソフトウェアを提供しています。CyberShielding Systems Inc.は、20年以上にわたり、高度な製品とサービスを通じて様々な企業のネットワークセキュリティ強化を支援してきました。情報およびネットワークセキュリティ分野で高い評価を得たCyberShielding Systems Inc.は、ISO/IEC 27001に基づくセキュリティ情報管理システム(ISMS)を導入し、認証を取得することで、自社および顧客の資産をより安全に保護し、競争優位性を獲得することを決定しました。 認証機関は、CyberShielding Systems Inc.のISO認証のための監査チームを選定することでプロセスを開始した。 IEC 27001認証に関して、認証機関は各監査員の氏名と経歴情報を同社に提供しました。しかし、CyberShielding Systems Inc.が確認したところ、監査員の1人が認証機関が要求するセキュリティクリアランスを保持していないことが判明しました。そのため、同社はこの監査員の任命に異議を申し立てました。認証機関は、CyberShielding Systems Inc.の異議申し立てを受けて、審査の結果、当該監査員を交代させました。 監査プロセスの一環として、CyberShielding Systems Inc.のリスクおよび機会の特定に関するアプローチが独立した活動として評価されました。これには、組織のリスクおよび機会の特定と管理方法を検証することが含まれていました。監査チームの主要な目的は、CyberShielding Systems Inc.のリスクおよび機会の特定メカニズムの有効性を保証すること、および特定されたリスクおよび機会に対処するための組織の戦略をレビューすることでした。この過程で、監査チームはファイアウォール構成レビュープロセスにおける監督の不備に起因するリスクも特定しました。このプロセスでは、適切な承認なしに変更が実施され、会社が脆弱性にさらされる可能性がありました。この発見は、このような問題を防止するためのより強力な内部統制の必要性を浮き彫りにしました。 監査チームは、主要な業務プロセスと統制を理解するために、プロセス記述書と組織図を参照しました。サードパーティのサービスプロバイダーの制限によりITインフラストラクチャとアプリケーションへのアクセスが制限されていたため、ITリスクと統制に関する分析は限定的なものとなりました。しかし、監査チームは、サイバーシールド社のISMSにおいて重大な欠陥が発生するリスクは低いと判断しました。これは、同社のプロセスのほとんどが自動化されているためです。そこで、監査チームは、サイバーシールド社の担当者に対し、IT責任、統制の有効性、マルウェア対策について質問し、ISMS全体が標準要件に適合していると評価しました。サイバーシールド社の担当者は、これらの質問すべてに十分かつ適切な証拠を提供しました。 監査前に締結された、監査の範囲、基準、目的を概説した合意書にもかかわらず、監査は主に、確立された基準への適合性を評価し、法令および規制要件への準拠を確保することに重点が置かれた。 質問 監査チームによるCyberShielding Systems Inc.のリスクと機会の特定に関する評価は、確立された監査基準に従って実施されましたか?シナリオ5を参照してください。
正解:A
The audit team's approach to assessing risk and opportunity determination as a standalone activity is in line with established auditing norms, making option A the correct answer. ISO/IEC 27001:2022 requires organizations to identify risks and opportunities related to the ISMS and to plan actions to address them. From an audit perspective, ISO 19011 allows auditors to structure audit activities in a way that ensures effective coverage of critical requirements. Assessing risk and opportunity determination independently does not violate auditing principles, provided it remains connected to the overall management system context. In practice, auditors often examine risk management as a distinct audit trail because it is a foundational element that influences many other ISMS processes, including control selection, operational planning, and continual improvement. Conducting a focused assessment enables auditors to evaluate whether risks are identified systematically, whether opportunities are considered, and whether treatment plans are appropriate and effective. Option C is incorrect because although risk and opportunity management should be embedded throughout the ISMS, auditing it as a standalone activity does not contradict this principle. It is an audit structuring decision rather than a management system design issue. Option B is incorrect because auditors do not require explicit auditee requests to structure audit activities independently; they are responsible for designing the audit approach. Therefore, the audit team's standalone assessment of risk and opportunity determination aligns with recommended auditing practices.