nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #105

Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an…

The correct answer is Clause 5.1 a; A.8.1; Clause 7.3; Clause 5.3. ISO/IEC 27001:2022 Drag-and-Drop Explanation Context: ABC nursing home uses electronic wristbands that upload resident health data (location, heartbeat, blood pressure) to an AI cloud server. The audit objective is verifying that top management established the information…

Conducting an Audit of an ISMS against ISO/IEC 27001

Question

Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that the electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff. The next step in your audit plan is to verify that the information security policy and objectives have been established by top management. During the audit, you found the following audit evidence. Match the audit evidence to the corresponding requirement in ISO/IEC 27001:2022. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #105 exhibit

Answer Area

Drag items

Clause 5.1 aClause 7.3A.8.1Clause 5.3

Correct arrangement

  • Clause 5.1 a
  • A.8.1
  • Clause 7.3
  • Clause 5.3

Explanation

ISO/IEC 27001:2022 Drag-and-Drop Explanation

Context: ABC nursing home uses electronic wristbands that upload resident health data (location, heartbeat, blood pressure) to an AI cloud server. The audit objective is verifying that top management established the information security policy and objectives.


The Correct Arrangement

1. Clause 5.1(a) - Leadership and Commitment

What it covers: Top management must demonstrate leadership by establishing the information security policy and ISMS objectives, ensuring they align with the organization's strategic direction.

Why it's first: The audit objective explicitly states verifying that "information security policy and objectives have been established by top management." This is the direct requirement. Typical audit evidence: a signed IS policy document, board meeting minutes approving the ISMS.

Common mistake: Confusing 5.1 (what top management must do) with 5.2 (what the policy itself must contain). The evidence here shows management action, not policy content.


2. A.8.1 - User Endpoint Devices

What it covers: Annex A control requiring that information stored on, processed by, or accessible via user endpoint devices is protected.

Why it fits here: The electronic wristbands are endpoint devices - they collect sensitive personal health data (biometrics, location) and transmit it to the cloud. Audit evidence maps here because it would address how the wristbands themselves are secured, configured, and managed.

Common mistake: Candidates sometimes reach for a data protection clause instead. A.8.1 is correct because the wristband is the device, and device-level controls are the first line of defense before data reaches the cloud.


3. Clause 7.3 - Awareness

What it covers: People working under the organization's control must be aware of the IS policy, their contribution to ISMS effectiveness, and the consequences of non-conformity.

Why it fits here: Healthcare staff access and act on the wristband data. Audit evidence here would be training records, awareness materials, or staff sign-offs confirming they understand the IS policy - particularly important given the sensitivity of resident health data.

Common mistake: Mixing up 7.2 (Competence - skills/qualifications) and 7.3 (Awareness - knowing about the policy). Awareness doesn't require training certificates; it requires evidence staff know the policy exists and why it matters.


4. Clause 5.3 - Organizational Roles, Responsibilities and Authorities

What it covers: Top management must assign and communicate IS roles and responsibilities throughout the organization.

Why it's last: After the policy is established (5.1a) and controls are in place (A.8.1) and staff are aware (7.3), the audit evidence here confirms who is accountable - e.g., an assigned Data Protection Officer, an ISMS manager, or documented role descriptions with IS responsibilities.

Common mistake: Candidates often place 5.3 first, assuming "assign roles before doing anything." In audit evidence matching, 5.3 evidence looks like org charts or role assignment documents - distinct from policy documents (5.1a) or awareness records (7.3).


Summary Table

PositionClauseCore Audit Question
15.1(a)Did top management establish the IS policy?
2A.8.1Are the wristband endpoint devices protected?
37.3Are healthcare staff aware of the IS policy?
45.3Are IS roles and responsibilities assigned?

Key insight: Clauses 5.1(a), 5.3 are both "top management" clauses - the distinction is establishing policy (5.1a) vs. assigning who owns it (5.3). Don't conflate them.

Topics

#information security policy#security objectives#top management commitment#audit evidence mapping

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice