nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #121

You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government…

The correct answer is B. This control requires the organisation to label information assets in accordance with the E. This control requires the organisation to protect the privacy and the rights of individuals whose G. This control requires the organisation to ensure that all employees and contractors are aware. The three Annex A controls that you would expect the auditee to have implemented when you conduct the follow-up audit are: information classification scheme, and to handle them accordingly12. This control is relevant for the auditee because it could help them to avoid…

Information Security Controls (Annex A)

Question

You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government offices. Parcels typically contain pharmaceutical products, biological samples, and documents such as passports and driving licences. You note that the company records show a very large number of returned items with causes including misaddressed labels and, in 15% of cases, two or more labels for different addresses for the one package. You are interviewing the Shipping Manager (SM). You: Are items checked before being dispatched? SM: Any obviously damaged items are removed by the duty staff before being dispatched, but the small profit margin makes it uneconomic to implement a formal checking process. You: What action is taken when items are returned? SM: Most of these contracts are relatively low value, therefore it has been decided that it is easier and more convenient to simply reprint the label and re-send individual parcels than it is to implement an investigation. You raise a nonconformity. Referencing the scenario, which three of the following Annex A controls would you expect the auditee to have implemented when you conduct the follow-up audit?

Options

  • A5.11 Return of assets
  • BThis control requires the organisation to label information assets in accordance with the
  • C5.3 Segregation of duties
  • D5.32 Intellectual property rights
  • EThis control requires the organisation to protect the privacy and the rights of individuals whose
  • F5.6 Contact with special interest groups
  • GThis control requires the organisation to ensure that all employees and contractors are aware
  • H6.4 Disciplinary process

How the community answered

(25 responses)
  • A
    24% (6)
  • B
    44% (11)
  • C
    4% (1)
  • D
    8% (2)
  • F
    16% (4)
  • H
    4% (1)

Explanation

The three Annex A controls that you would expect the auditee to have implemented when you conduct the follow-up audit are: information classification scheme, and to handle them accordingly12. This control is relevant for the auditee because it could help them to avoid misaddressing labels and sending parcels to wrong destinations, which could compromise the confidentiality, integrity, and availability of the information assets. By labelling the information assets correctly, the auditee could also ensure that they are delivered to the intended recipients and that they are protected from unauthorized access, use, or disclosure. personal identifiable information (PII) is processed by the organisation, and to comply with the applicable legal and contractual obligations13. This control is relevant for the auditee because it could help them to prevent the unauthorized use of residents' personal data by a supplier, which could violate the privacy and the rights of the residents and their family members, and expose the auditee to legal and reputational risks. By protecting the PII of the residents and their family members, the auditee could also enhance their trust and satisfaction, and avoid complaints and of the information security policy, their roles and responsibilities, and the relevant information security procedures and controls14. This control is relevant for the auditee because it could help them to improve the information security culture and behaviour of their staff, and to reduce the human errors and negligence that could lead to information security incidents. By providing information security awareness, education, and training to their staff, the auditee could also increase their competence and performance, and ensure the effectiveness and efficiency of the information security processes and controls.

Topics

#information labeling#asset management#privacy protection#security awareness

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice