Question 1 of 30
GlobalTech Solutions, a multinational manufacturing company headquartered in Germany, is expanding its operations into Brazil. Brazil has stringent data privacy laws, including the Lei Geral de Proteção de Dados (LGPD), which are significantly different from the GDPR that GlobalTech Solutions is accustomed to complying with in Europe. The company processes sensitive customer data, intellectual property related to its manufacturing processes, and employee information. GlobalTech\'s existing Information Security Management System (ISMS) is certified under ISO 27001:2013, and they are transitioning to align with ISO 27002:2022. As the newly appointed Information Security Manager, you are tasked with ensuring that the expansion into Brazil does not compromise the company\'s information security posture and complies with all relevant legal and regulatory requirements. Considering the principles outlined in ISO 27002:2022 regarding risk management, legal compliance, and continuous improvement, what is the MOST effective approach to address the information security challenges associated with this expansion?
Conduct a comprehensive risk assessment specifically tailored to the Brazilian context, mapping identified risks against LGPD requirements and other relevant local regulations. Adapt existing security controls and implement new controls as necessary to address these risks and ensure compliance, creating a risk-regulation-control matrix for ongoing monitoring and auditing.
Primarily focus on aligning GlobalTech's existing ISMS policies and procedures with the company's global standards, assuming that the GDPR compliance framework is sufficiently robust to cover most aspects of the LGPD. Implement only minor adjustments to address any perceived gaps.
Implement a set of generic security controls that are commonly used in the manufacturing industry, without specifically tailoring them to the legal and regulatory requirements of Brazil or conducting a detailed risk assessment of the local operating environment.
Outsource the entire information security compliance process to a local Brazilian consulting firm, relying solely on their expertise to manage the company's security risks and ensure compliance with local laws, without retaining significant internal oversight or control.

Preparing for ISO 27002:2022 – Information Security Controls? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free