Question 1 of 30
\"GlobalVest Advisors,\" a multinational investment firm, has historically focused on traditional asset classes such as equities and fixed income. Their ISMS, certified under ISO 27001:2022, is well-established and aligned with the regulatory requirements of the jurisdictions in which they operate, including GDPR and the California Consumer Privacy Act (CCPA). Recently, GlobalVest\'s board approved an expansion of their investment mandate to include a significant allocation to alternative investments, specifically private equity and hedge funds. This expansion necessitates handling highly sensitive, non-public information related to these investments, including deal terms, financial models, and investor data. To ensure continued compliance and effective risk management, what is the MOST crucial initial action GlobalVest\'s Lead ISMS Auditor should recommend?
Conduct a comprehensive risk assessment focused on the new alternative investment portfolio, identifying specific threats and vulnerabilities related to the handling of sensitive, non-public information, and update the ISMS scope and objectives accordingly.
Immediately implement a firm-wide ban on the use of personal devices for accessing any investment-related information, regardless of asset class, to minimize the risk of data leakage.
Increase the frequency of internal ISMS audits from annually to quarterly to ensure that all existing controls are operating effectively across all asset classes.
Mandate that all employees involved in the alternative investment portfolio complete a generic cybersecurity awareness training program, focusing on phishing and malware prevention.

Preparing for ISO 27001:2022 – Information Security Management System Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free