nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #132

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external…

The correct answer is A. Access to and from the loading bay B. How power and data cables enter the building F. The operation of the site CCTV and door control systems G. The organisation's arrangements for maintaining equipment. The four controls from the list that are related to PHYSICAL aspects of the ISMS are: Access to and from the loading bay How power and data cables enter the building The operation of the site CCTV and door control systems The organisation's arrangements for maintaining…

Information Security Controls (Annex A) - Physical

Question

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the PHYSICAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.

Options

  • AAccess to and from the loading bay
  • BHow power and data cables enter the building
  • CInformation security awareness, education, and training
  • DThe conducting of verification checks on personnel
  • EThe development and maintenance of an information asset inventory
  • FThe operation of the site CCTV and door control systems
  • GThe organisation's arrangements for maintaining equipment
  • HThe organisation's business continuity arrangements

How the community answered

(61 responses)
  • A
    77% (47)
  • C
    13% (8)
  • D
    5% (3)
  • E
    3% (2)
  • H
    2% (1)

Explanation

The four controls from the list that are related to PHYSICAL aspects of the ISMS are: Access to and from the loading bay How power and data cables enter the building The operation of the site CCTV and door control systems The organisation's arrangements for maintaining equipment These controls are derived from the ISO 27001 Annex A, which provides a comprehensive list of information security controls that can be applied to an ISMS1. The other controls in the list are more related to ORGANIZATIONAL, LEGAL, or HUMAN aspects of the ISMS, which are also important, but not the focus of this question. According to the ISMS Auditing Guideline2, the auditor in training should review the PHYSICAL Checking the SoA to identify the applicable controls and their implementation status Interviewing the relevant staff and management to verify their understanding and involvement in Observing the physical and environmental conditions to confirm the existence and effectiveness Examining the relevant documents and records to validate the compliance and performance of

Topics

#physical controls#Statement of Applicability#data center security#Annex A controls

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice