Corvus Publishing runs patching to keep systems current and monitoring tools that alert on suspicious activity, but the board accepts that a ransomware attack could still succeed and encrypt its production servers. The board asks internal audit for the control that would best remediate the effects and restore operations if an attack does get through. Which control should the auditor recommend?
- AA recurring phishing-awareness programme so that staff are less likely to open the malicious attachments that carry ransomware.
- BRegularly tested offline backups with a documented procedure to restore encrypted systems to a clean prior state. Correct
- CIntrusion-detection tooling that raises an alert as soon as unusual bulk file-encryption behaviour is observed on the network.
- DNetwork segmentation designed to stop malware from spreading laterally between the organisation's server environments.
Why A is wrong: Awareness training reduces the chance that an attack starts, which is preventive, so it does not remediate the damage once servers have already been encrypted.
Why B is correct: Restoring from tested backups repairs the effect of a successful attack and returns operations to normal, which is exactly the corrective control the board's stated aim requires.
Why C is wrong: Alerting on encryption in progress is a detective control that tells the organisation an event is happening, but it does not by itself restore the encrypted systems.
Why D is wrong: Segmentation limits how far an attack can travel, so it works to prevent wider compromise rather than to recover the systems that have already been encrypted.