Special Offer! Get 25% Off on All Certification Exam Questions. Use Code: HELLO20OFF
Scenario 5: Operaze is a small software development company that develops applications for various
companies around the world. Recently, the company conducted a risk assessment to assess the information
security risks that could arise from operating in a digital landscape. Using different testing methods, including
penetration Resting and code review, the company identified some issues in its ICT systems, including
improper user permissions, misconfigured security settings, and insecure network configurations. To resolve
these issues and enhance information security, Operaze decided to implement an information security
management system (ISMS) based on ISO/IEC 27001.
Considering that Operaze is a small company, the entire IT team was involved in the ISMS implementation
project. Initially, the company analyzed the business requirements and the internal and external environment,
identified its key processes and activities, and identified and analyzed theinterested parties In addition, the top
management of Operaze decided to Include most of the company's departments within the ISMS scope. The
defined scope included the organizational and physical boundaries. The IT team drafted an information
security policy and communicated it to all relevant interested parties In addition, other specific policies were
developed to elaborate on security issues and the roles and responsibilities were assigned to all interested
parties.
Following that, the HR manager claimed that the paperwork created by ISMS does not justify its value and the
implementation of the ISMS should be canceled However, the top management determined that this claim was
invalid and organized an awareness session to explain the benefits of the ISMS to all interested parties.
Operaze decided to migrate Its physical servers to their virtual servers on third-party infrastructure. The new
cloud computing solution brought additional changes to the company Operaze's top management, on the other
hand, aimed to not only implement an effective ISMS but also ensure the smooth running of the ISMS
operations. In this situation, Operaze's top management concluded that the services of external experts were
required to implement their information security strategies. The IT team, on the other hand, decided to initiate
a change in the ISMS scope and implemented the required modifications to the processes of the company.
What is the next step that Operaze's ISMS implementation team should take after drafting the information
security policy? Refer to scenario 5.
© Copyrights Dumpscity 2025. All Rights Reserved
We use cookies to ensure your best experience. So we hope you are happy to receive all cookies on the Dumpscity.