情報セキュリティ管理
- ISMS(情報セキュリティマネジメントシステム):組織全体でセキュリティを管理する体制・ISO 27001認証
- セキュリティポリシー:組織としてのセキュリティ方針・規則を文書化したもの
- リスクアセスメント:資産を洗い出し、脅威・脆弱性・影響を評価して対策を決定する
- インシデント対応:発生時の手順(検知→初動→調査→回復→再発防止)
- ISMS (Information Security Management System) — a systematic approach to managing security across the organisation. ISO/IEC 27001 is the internationally recognised certification.
- Security policy — the company's written rules: who can access what, how data is handled, what to do if a breach occurs.
- Risk assessment: List assets → identify threats → assess likelihood × impact → choose controls (avoid, reduce, transfer, accept).
- Incident response: Detect → Contain → Investigate → Recover → Prevent recurrence.
- ISMS — အဖွဲ့အစည်းတစ်ခုလုံးတွင် လုံခြုံရေး စီမံခန့်ခွဲမှု ကျစ်လျစ်သော နည်းလမ်း。ISO 27001 သည် နိုင်ငံတကာ အသိအမှတ်ပြု လက်မှတ်ဖြစ်သည်。
- Security policy — မည်သူမည်ဝါ ဘာကိုဝင်ရောက်ကြည့်ရှုနိုင်သည်၊ ဒေတာ မည်သို့ကိုင်တွယ်သင့်သည်ဟု company ၏ စာဖြင့်ရေးထားသောနည်းဥပဒေ。
Related Practice Questions
ဆက်စပ် လေ့ကျင့်ခန်းမေးခွန်းများ
Of the following statements about internal controls in ITSMS, which is the most appropriate?
ITSMS (IT ဝန်ဆောင်မှုစီမံခန့်ခွဲမှုစနစ်) တွင် အတွင်းပိုင်းထိန်းချုပ်မှုနှင့်ပတ်သက်သော ဖော်ပြချက်များအနက် အသင့်တော်ဆုံးသည်မှာ အဘယ်နည်း?
In the 'Login Records' and 'Department' tables below, which lists ONLY the departments of employees who have either had a failed login or had a successful login on or after April 13, 2022? Login Records: | DateTime | Emp No. | Dept No. | Result | |---|---|---|---| |2022-04-12 08:36:47 | 10004 | 003 | Failed | |2022-04-12 09:51:15 | 10005 | 001 | Success | |2022-04-12 09:55:48 | 10001 | 007 | Success | |2022-04-13 01:28:37 | 10004 | 002 | Success | |2022-04-14 09:22:18 | 10007 | 003 | Failed | |2022-04-14 10:02:08 | 10011 | 001 | Success | |2022-04-18 18:25:55 | 10001 | 001 | Success | Departments: | Dept No. | Dept Name | |---|---| | 001 | Sales | | 002 | Systems | | 003 | HR |
အောက်ပါ 'Login မှတ်တမ်း' နှင့် 'ဌာန' ဇယားများတွင် login မအောင်မြင်မှု ရှိသော သို့မဟုတ် ဧပြီ ၁၃ ရက် ၂၀၂၂ နောက်ပိုင်း login အောင်မြင်မှုရှိသော ဝန်ထမ်းများ ပါဝင်သော ဌာနများကိုသာ ဖော်ပြသည်မှာ အဘယ်နည်း? Login မှတ်တမ်း: | ရက်/ချိန် | ဝန်ထမ်းနံပါတ် | ဌာနနံပါတ် | ရလဒ် | |---|---|---|---| |2022-04-12 08:36:47 | 10004 | 003 | မအောင်မြင် | |2022-04-12 09:51:15 | 10005 | 001 | အောင်မြင် | |2022-04-12 09:55:48 | 10001 | 007 | အောင်မြင် | |2022-04-13 01:28:37 | 10004 | 002 | အောင်မြင် | |2022-04-14 09:22:18 | 10007 | 003 | မအောင်မြင် | |2022-04-14 10:02:08 | 10011 | 001 | အောင်မြင် | |2022-04-18 18:25:55 | 10001 | 001 | အောင်မြင် | ဌာန: | ဌာနနံပါတ် | ဌာနအမည် | |---|---| | 001 | ရောင်းချမှုဌာန | | 002 | စနစ်ဌာန | | 003 | HR ဌာန |
Which is the most appropriate example of activities carried out by a CIRT?
CIRT (Computer Incident Response Team) မှ ဆောင်ရွက်သော လှုပ်ရှားမှုဥပမာအဖြစ် အသင့်တော်ဆုံးသည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?
Which is an appropriate description of digital forensics?
Digital forensics ၏ ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?
Which is an appropriate description of an information security policy in ISMS?
ISMS (Information Security Management System) ရှိ သတင်းအချက်အလက်လုံခြုံရေး မူဝါဒနှင့်ပတ်သက်သော ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?
Which is an appropriate description of risk treatment in information security risk management?
သတင်းအချက်အလက်လုံခြုံရေး risk စီမံခန့်ခွဲမှုတွင် risk treatment (risk ကိုင်တွယ်ဆောင်ရွက်မှု) ၏ ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?