ISO-IEC-27001-LEAD-AUDITOR · Question #105
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an…
The correct answer is Clause 5.1 a; A.8.1; Clause 7.3; Clause 5.3. ISO/IEC 27001:2022 Drag-and-Drop Explanation Context: ABC nursing home uses electronic wristbands that upload resident health data (location, heartbeat, blood pressure) to an AI cloud server. The audit objective is verifying that top management established the information…
Question
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that the electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff. The next step in your audit plan is to verify that the information security policy and objectives have been established by top management. During the audit, you found the following audit evidence. Match the audit evidence to the corresponding requirement in ISO/IEC 27001:2022. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Clause 5.1 a
- A.8.1
- Clause 7.3
- Clause 5.3
Explanation
ISO/IEC 27001:2022 Drag-and-Drop Explanation
Context: ABC nursing home uses electronic wristbands that upload resident health data (location, heartbeat, blood pressure) to an AI cloud server. The audit objective is verifying that top management established the information security policy and objectives.
The Correct Arrangement
1. Clause 5.1(a) - Leadership and Commitment
What it covers: Top management must demonstrate leadership by establishing the information security policy and ISMS objectives, ensuring they align with the organization's strategic direction.
Why it's first: The audit objective explicitly states verifying that "information security policy and objectives have been established by top management." This is the direct requirement. Typical audit evidence: a signed IS policy document, board meeting minutes approving the ISMS.
Common mistake: Confusing 5.1 (what top management must do) with 5.2 (what the policy itself must contain). The evidence here shows management action, not policy content.
2. A.8.1 - User Endpoint Devices
What it covers: Annex A control requiring that information stored on, processed by, or accessible via user endpoint devices is protected.
Why it fits here: The electronic wristbands are endpoint devices - they collect sensitive personal health data (biometrics, location) and transmit it to the cloud. Audit evidence maps here because it would address how the wristbands themselves are secured, configured, and managed.
Common mistake: Candidates sometimes reach for a data protection clause instead. A.8.1 is correct because the wristband is the device, and device-level controls are the first line of defense before data reaches the cloud.
3. Clause 7.3 - Awareness
What it covers: People working under the organization's control must be aware of the IS policy, their contribution to ISMS effectiveness, and the consequences of non-conformity.
Why it fits here: Healthcare staff access and act on the wristband data. Audit evidence here would be training records, awareness materials, or staff sign-offs confirming they understand the IS policy - particularly important given the sensitivity of resident health data.
Common mistake: Mixing up 7.2 (Competence - skills/qualifications) and 7.3 (Awareness - knowing about the policy). Awareness doesn't require training certificates; it requires evidence staff know the policy exists and why it matters.
4. Clause 5.3 - Organizational Roles, Responsibilities and Authorities
What it covers: Top management must assign and communicate IS roles and responsibilities throughout the organization.
Why it's last: After the policy is established (5.1a) and controls are in place (A.8.1) and staff are aware (7.3), the audit evidence here confirms who is accountable - e.g., an assigned Data Protection Officer, an ISMS manager, or documented role descriptions with IS responsibilities.
Common mistake: Candidates often place 5.3 first, assuming "assign roles before doing anything." In audit evidence matching, 5.3 evidence looks like org charts or role assignment documents - distinct from policy documents (5.1a) or awareness records (7.3).
Summary Table
| Position | Clause | Core Audit Question |
|---|---|---|
| 1 | 5.1(a) | Did top management establish the IS policy? |
| 2 | A.8.1 | Are the wristband endpoint devices protected? |
| 3 | 7.3 | Are healthcare staff aware of the IS policy? |
| 4 | 5.3 | Are IS roles and responsibilities assigned? |
Key insight: Clauses 5.1(a), 5.3 are both "top management" clauses - the distinction is establishing policy (5.1a) vs. assigning who owns it (5.3). Don't conflate them.
Topics
Community Discussion
No community discussion yet for this question.
