PECB ISO-IEC-27001-Lead-Implementer Question Answer
NoAVision is a mid-sized cybersecurity solutions provider based in Tartu, Estonia, with satellite offices in Stockholm and Berlin. The company specializes in secure cloud hosting, identity and access management (IAM), and digital certificate lifecycle management. Its clients span the government, financial services, and healthcare sectors. To have a structured approach to safeguarding sensitive information, NoAVision decided to implement an ISMS based on ISO/IEC 27001. During risk assessment, the security team at NoAVision identified two critical vulnerabilities: inadequate maintenance and faulty installation of data storage media, and the absence of mechanisms to confirm the successful transmission and receipt of internal communications. These weaknesses posed threats to data integrity and availability, prompting the company to prioritize remediation.
What category of vulnerabilities did NoAVision identify during its risk assessment?

