PrepIPA
HomeStudyIP Guide › Topic 62
💻 Technology 62 / 63
62

情報セキュリティ管理

Information Security Management
သတင်းအချက်အလက် လုံခြုံရေး စီမံခန့်ခွဲမှု
🇯🇵 日本語
  • ISMS(情報セキュリティマネジメントシステム):組織全体でセキュリティを管理する体制・ISO 27001認証
  • セキュリティポリシー:組織としてのセキュリティ方針・規則を文書化したもの
  • リスクアセスメント:資産を洗い出し、脅威・脆弱性・影響を評価して対策を決定する
  • インシデント対応:発生時の手順(検知→初動→調査→回復→再発防止)
🇬🇧 English
  • ISMS (Information Security Management System) — a systematic approach to managing security across the organisation. ISO/IEC 27001 is the internationally recognised certification.
  • Security policy — the company's written rules: who can access what, how data is handled, what to do if a breach occurs.
  • Risk assessment: List assets → identify threats → assess likelihood × impact → choose controls (avoid, reduce, transfer, accept).
  • Incident response: Detect → Contain → Investigate → Recover → Prevent recurrence.
🇲🇲 မြန်မာ
  • ISMS — အဖွဲ့အစည်းတစ်ခုလုံးတွင် လုံခြုံရေး စီမံခန့်ခွဲမှု ကျစ်လျစ်သော နည်းလမ်း。ISO 27001 သည် နိုင်ငံတကာ အသိအမှတ်ပြု လက်မှတ်ဖြစ်သည်。
  • Security policy — မည်သူမည်ဝါ ဘာကိုဝင်ရောက်ကြည့်ရှုနိုင်သည်၊ ဒေတာ မည်သို့ကိုင်တွယ်သင့်သည်ဟု company ၏ စာဖြင့်ရေးထားသောနည်းဥပဒေ。
Keywords
ISMSISO27001セキュリティポリシーリスクアセスメントインシデント対応
← 61 62 / 63 63 →

Related Practice Questions

ဆက်စပ် လေ့ကျင့်ခန်းမေးခွန်းများ

IP 2025 Q59

Of the following statements about internal controls in ITSMS, which is the most appropriate?

ITSMS (IT ဝန်ဆောင်မှုစီမံခန့်ခွဲမှုစနစ်) တွင် အတွင်းပိုင်းထိန်းချုပ်မှုနှင့်ပတ်သက်သော ဖော်ပြချက်များအနက် အသင့်တော်ဆုံးသည်မှာ အဘယ်နည်း?

★★★
IP 2025 Q66

In the 'Login Records' and 'Department' tables below, which lists ONLY the departments of employees who have either had a failed login or had a successful login on or after April 13, 2022? Login Records: | DateTime | Emp No. | Dept No. | Result | |---|---|---|---| |2022-04-12 08:36:47 | 10004 | 003 | Failed | |2022-04-12 09:51:15 | 10005 | 001 | Success | |2022-04-12 09:55:48 | 10001 | 007 | Success | |2022-04-13 01:28:37 | 10004 | 002 | Success | |2022-04-14 09:22:18 | 10007 | 003 | Failed | |2022-04-14 10:02:08 | 10011 | 001 | Success | |2022-04-18 18:25:55 | 10001 | 001 | Success | Departments: | Dept No. | Dept Name | |---|---| | 001 | Sales | | 002 | Systems | | 003 | HR |

အောက်ပါ 'Login မှတ်တမ်း' နှင့် 'ဌာန' ဇယားများတွင် login မအောင်မြင်မှု ရှိသော သို့မဟုတ် ဧပြီ ၁၃ ရက် ၂၀၂၂ နောက်ပိုင်း login အောင်မြင်မှုရှိသော ဝန်ထမ်းများ ပါဝင်သော ဌာနများကိုသာ ဖော်ပြသည်မှာ အဘယ်နည်း? Login မှတ်တမ်း: | ရက်/ချိန် | ဝန်ထမ်းနံပါတ် | ဌာနနံပါတ် | ရလဒ် | |---|---|---|---| |2022-04-12 08:36:47 | 10004 | 003 | မအောင်မြင် | |2022-04-12 09:51:15 | 10005 | 001 | အောင်မြင် | |2022-04-12 09:55:48 | 10001 | 007 | အောင်မြင် | |2022-04-13 01:28:37 | 10004 | 002 | အောင်မြင် | |2022-04-14 09:22:18 | 10007 | 003 | မအောင်မြင် | |2022-04-14 10:02:08 | 10011 | 001 | အောင်မြင် | |2022-04-18 18:25:55 | 10001 | 001 | အောင်မြင် | ဌာန: | ဌာနနံပါတ် | ဌာနအမည် | |---|---| | 001 | ရောင်းချမှုဌာန | | 002 | စနစ်ဌာန | | 003 | HR ဌာန |

★★★★
IP 2025 Q68

Which is the most appropriate example of activities carried out by a CIRT?

CIRT (Computer Incident Response Team) မှ ဆောင်ရွက်သော လှုပ်ရှားမှုဥပမာအဖြစ် အသင့်တော်ဆုံးသည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?

★★★
IP 2025 Q74

Which is an appropriate description of digital forensics?

Digital forensics ၏ ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?

★★★
IP 2025 Q84

Which is an appropriate description of an information security policy in ISMS?

ISMS (Information Security Management System) ရှိ သတင်းအချက်အလက်လုံခြုံရေး မူဝါဒနှင့်ပတ်သက်သော ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?

★★★
IP 2025 Q91

Which is an appropriate description of risk treatment in information security risk management?

သတင်းအချက်အလက်လုံခြုံရေး risk စီမံခန့်ခွဲမှုတွင် risk treatment (risk ကိုင်တွယ်ဆောင်ရွက်မှု) ၏ ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?

★★★
See all IP questions →
← 61 62 / 63 63 →