ISO-IEC-27001-LEAD-AUDITOR · Question #110
You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 10 user accounts on…
The correct answer is B. Collect more evidence on how the transition of Scott from full-time to part-time employment was D. Collect more evidence of why Scott resigned and whether his re-engagement represents a G. Collect more evidence on how the organization pays for Scott's source code maintenance support. The options B, D, and G are not valid audit trails because they are not directly related to the ISMS requirements or the audit criteria. They are more relevant to the human resource management or the contractual arrangements of the organization, which are outside the scope of…
Question
You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 10 user accounts on the SCM. You confirm that one of the users, Scott, resigned 9-months ago. The SCM System Administrator confirmed Scott's last check-out of the source code was found 1 month ago. He was using one of the uthorized desktops from the local network in a secure area. You check with the user de-registration procedure which states "Managers have to make sure of deregistration of the user account and authorisation immediately from the relevant ICT system and/or equipment after resignation approval." There was no deregistration record for user Scott. The IT Security Manager explains that Scott still comes back to the office every month after he resigned to provide support on source code maintenance. That's why his account on SCM still exists. You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.
Options
- ACollect more evidence on how access controls are periodically reviewed to maintain security
- BCollect more evidence on how the transition of Scott from full-time to part-time employment was
- CCollect more evidence from Scott's background verification checks performed by the human
- DCollect more evidence of why Scott resigned and whether his re-engagement represents a
- ECollect more evidence on how Scott can access the employee's desktop and local network.
- FCollect more evidence on how Scott can access the secure area (Relevant to control A.8.4)
- GCollect more evidence on how the organization pays for Scott's source code maintenance support
- HCollect more evidence on where Scott kept the source code that he checked out and how it was
How the community answered
(45 responses)- A2% (1)
- B60% (27)
- C11% (5)
- E4% (2)
- F20% (9)
- H2% (1)
Explanation
The options B, D, and G are not valid audit trails because they are not directly related to the ISMS requirements or the audit criteria. They are more relevant to the human resource management or the contractual arrangements of the organization, which are outside the scope of the ISMS audit. The other options are valid audit trails because they can provide evidence of how the organization implements and maintains the ISMS controls related to access control, secure areas, and information security aspects of business continuity management.
Topics
Community Discussion
No community discussion yet for this question.