nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #109

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their…

The correct answer is B. This clause requires the organisation to determine the interested parties that are relevant to E. This clause requires the organisation to establish an information security policy that provides F. This clause requires the organisation to determine the internal and external issues that are H. This clause requires the organisation to determine the boundaries and applicability of the. the ISMS, and the requirements of these interested parties12. This clause is relevant to the verification of the scope of the ISMS because it helps the organisation to identify the stakeholders that have an influence or an interest in the information security of the…

Conducting an Audit of an ISMS against ISO/IEC 27001

Question

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that he electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff. To verify the scope of ISMS, you interview the management system representative (MSR) who explains that the ISMS scope covers an outsourced data center. Select four options for the clauses and/or controls of ISO/IEC 27001:2022 that are directly relevant to the verification of the scope of the ISMS.

Options

  • AControl 5.3 Organizational roles, responsibilites and authorities
  • BThis clause requires the organisation to determine the interested parties that are relevant to
  • CControl 5.3 Legal, statutory, regulatory and contractual requirements
  • DControl 6.3 Information security awareness, education, and training
  • EThis clause requires the organisation to establish an information security policy that provides
  • FThis clause requires the organisation to determine the internal and external issues that are
  • GControl 7.6 Working in secure areas
  • HThis clause requires the organisation to determine the boundaries and applicability of the

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    78% (21)
  • D
    11% (3)
  • G
    7% (2)

Explanation

the ISMS, and the requirements of these interested parties12. This clause is relevant to the verification of the scope of the ISMS because it helps the organisation to identify the stakeholders that have an influence or an interest in the information security of the organisation, such as customers, suppliers, regulators, employees, etc. The organisation should also consider the needs and expectations of these interested parties when defining the scope of the ISMS, and ensure that they are met and communicated. the framework for setting the information security objectives and guiding the information security activities13. This clause is relevant to the verification of the scope of the ISMS because it helps the organisation to define the direction and principles of the ISMS, and to align them with the strategic goals and context of the organisation. The information security policy should also be consistent with the scope of the ISMS, and should be communicated and understood within the organisation and by relevant interested parties. relevant to the purpose and the context of the organisation, and that affect its ability to achieve the intended outcomes of the ISMS14. This clause is relevant to the verification of the scope of the ISMS because it helps the organisation to understand the factors and conditions that influence the information security of the organisation, such as the legal, technological, social, economic, environmental, etc. The organisation should also monitor and review these issues, and consider them when defining the scope of the ISMS. ISMS to establish its scope15. This clause is relevant to the verification of the scope of the ISMS because it helps the organisation to describe the information and processes that are included in the ISMS, and to document the scope in a clear and concise manner. The organisation should also consider the issues, requirements, and interfaces identified in clauses 4.1, 4.2, and 4.3 when determining the scope of the ISMS, and ensure that the scope is appropriate to the nature and scale of the organisation.

Topics

#ISMS scope#interested parties#outsourced data center#ISO 27001 clause 4

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice