Q: 12
Scenario 2:
Beauty is a well-established cosmetics company in the beauty industry. The company was founded
several decades ago with a passion for creating high-quality skincare, makeup, and personal care
products that enhance natural beauty. Over the years, Beauty has built a strong reputation for its
innovative product offerings, commitment to customer satisfaction, and dedication to ethical and
sustainable business practices.
In response to the rapidly evolving landscape of consumer shopping habits, Beauty transitioned from
traditional retail to an e-commerce model. To initiate this strategy, Beauty conducted a
comprehensive information security risk assessment, analyzing potential threats and vulnerabilities
associated with its new e-commerce venture, aligned with its business strategy and objectives.
Concerning the identified risks, the company implemented several information security controls. All
employees were required to sign confidentiality agreements to emphasize the importance of
protecting sensitive customer dat
a. The company thoroughly reviewed user access rights, ensuring only authorized personnel could
access sensitive information. In addition, since the company stores valuable products and unique
formulas in the warehouse, it installed alarm systems and surveillance cameras with real-time alerts
to prevent any potential act of vandalism.
After a while, the information security team analyzed the audit logs to monitor and track activities
across the newly implemented security controls. Upon investigating and analyzing the audit logs, it
was discovered that an attacker had accessed the system due to out-of-date anti-malware software,
exposing customers' sensitive information, including names and home addresses. Following this, the
IT team replaced the anti-malware software with a new one capable of automatically removing
malicious code in case of similar incidents. The new software was installed on all workstations and
regularly updated with the latest malware definitions, with an automatic update feature enabled. An
authentication process requiring user identification and a password was also implemented to access
sensitive information.
During the investigation, Maya, the information security manager of Beauty, found that information
security responsibilities in job descriptions were not clearly defined, for which the company took
immediate action. Recognizing that their e-commerce operations would have a global reach, Beauty
diligently researched and complied with the industry's legal, statutory, regulatory, and contractual
requirements. It considered international and local regulations, including data privacy laws,
consumer protection acts, and global trade agreements.
To meet these requirements, Beauty invested in legal counsel and compliance experts who
continuously monitored and ensured the company's compliance with legal standards in every market
they operated in. Additionally, Beauty conducted multiple information security awareness sessions
for the IT team and other employees with access to confidential information, emphasizing the
importance of system and network security.
What type of assets were compromised in Beauty’s incident?
Options
Discussion
Its A, not B. The attacker got customer names and addresses, which are personal virtual assets, not company-only data.
Option B makes sense since the info exposed was linked to the company’s customer data and systems, so that could count as organizational virtual assets. But was the focus on actual customer personal data (like names and addresses) or just company digital property? If they mean the latter, B fits. Seen similar scenarios in official guides.
Be respectful. No spam.