Question 1 of 30
\"Maple Leaf Financial,\" a Canadian wealth management firm, is undergoing its initial ISO/IEC 27001:2022 certification audit. During the audit, the lead auditor discovers that while the firm has a comprehensive Information Security Management System (ISMS) in place, there is no formal data classification policy. Client data, including financial statements, investment portfolios, and personal identification information, is stored on a shared network drive with only basic access controls. The auditor notes that a recent internal risk assessment identified client data as a critical asset but did not specify any specific security controls beyond standard password protection. Furthermore, the firm has not fully addressed compliance requirements under Canadian privacy laws concerning the protection of personal financial information. Given this scenario and the requirements of ISO/IEC 27001:2022, what is the MOST appropriate immediate action that Maple Leaf Financial should take to address this gap in their ISMS and ensure the confidentiality, integrity, and availability of client data?
Develop and implement a data classification policy to determine appropriate security controls based on the sensitivity of the client data.
Immediately encrypt all data on the shared network drive and implement multi-factor authentication for all users.
Conduct a penetration test to identify vulnerabilities in the network infrastructure and address any identified weaknesses.
Purchase cyber insurance to mitigate the financial impact of potential data breaches involving client information.

Preparing for ISO/IEC 27001:2022 - Information Security Management Systems Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free