Q: 3
Scenario 1: NobleFind is an online retailer specializing in high-end, custom-design furniture. The
company offers a wide range of handcrafted pieces tailored to meet the needs of residential and
commercial clients. NobleFind also provides expert design consultation services. Despite NobleFind's
efforts to keep its online shop platform secure, the company faced persistent issues, including a
recent data breach. These ongoing challenges disrupted normal operations and underscored the
need for enhanced security measures. The designated IT team quickly responded to resolve the
problem, demonstrating their agility in handling technical challenges. To address these issues,
NobleFind decided to implement an Information Security Management System (ISMS) based on
ISO/IEC 27001 to improve security, protect customer data, and ensure the stability of its services.
In addition to its commitment to information security, NobleFind focuses on maintaining the
accuracy and completeness of its product dat
a. This is ensured by carefully managing version control, checking information regularly, enforcing
strict access policies, and implementing backup procedures. Product details and customer designs
are accessible only to authorized individuals, with security measures such as multi-factor
authentication and data access policies. NobleFind has implemented an incident investigation
process within its ISMS and established record retention policies. NobleFind maintains and
safeguards documented information, encompassing a wide range of data, records, and
specifications—ensuring the security and integrity of customer data, historical records, and financial
information.
Has NobleFind implemented any preventive controls? Refer to Scenario 1.
Options
Discussion
A tbh
I thought C made sense since most examples were incident response and audits, not actual prevention.
A . Official ISO/IEC 27001 docs and the main textbook both list policy as a preventive control. Check those if unsure.
Pretty sure it's A, since having an information security policy is itself a preventive control under ISO 27001. The scenario mentions that explicitly, so I think that fits the definition. Let me know if you see it differently.
Option C, since the scenario mostly covers detective and corrective actions, not much on prevention except maybe policies.
Probably C, but I'd check the official guide or some practice tests for how ISO 27001 defines preventive controls.
Be respectful. No spam.