ISO 30301:2019 Information and documentation -- Management systems for records Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

GlobalTech Solutions, a multinational corporation, is implementing ISO 30301:2019 to enhance its records management practices. The company already has a well-established risk management framework based on ISO 31000. During a recent risk assessment related to records management, a significant risk was identified: potential data breaches stemming from inadequate access controls on legacy systems that store sensitive customer data. These legacy systems are critical for specific business functions and cannot be immediately replaced. The company\'s Chief Information Security Officer (CISO), Anya Sharma, is tasked with determining the most appropriate risk treatment option, considering the limited budget and the need to maintain business continuity. The legal department has emphasized the importance of complying with GDPR and other data protection regulations. What would be the MOST appropriate risk treatment option for Anya to recommend in this scenario, aligning with ISO 30301:2019 and ISO 31000 principles, while balancing risk mitigation, cost, and operational needs?

Implement enhanced access controls, such as multi-factor authentication, regular security audits, and employee training on data protection, to reduce the likelihood and impact of data breaches.
Completely decommission the legacy systems and migrate all data to a new, more secure platform, regardless of the immediate cost and potential disruption to business operations.
Transfer the risk by purchasing a comprehensive cybersecurity insurance policy that covers potential data breach losses and legal liabilities.
Accept the risk and monitor the legacy systems for any signs of unauthorized access, as the cost of implementing new security measures is deemed too high.

About the ISO 30301:2019 Information and documentation -- Management systems for records Certification

These free practice questions are designed to help you assess your readiness for the ISO 30301:2019 Information and documentation -- Management systems for records exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.