ISO-IEC-27001-LEAD-AUDITOR · Question #135
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process…
The correct answer is E. Collect more evidence on how the organisation manages the Point of Contact (PoC) which G. Collect more evidence on whether terms and definitions are contained in the information security H. Collect more evidence to determine if ISO 27035 (Information security incident management) is. These options are not valid audit trails because they are not directly related to the information security incident management process, which is the focus of the audit. The audit trails should be relevant to the objectives, scope, and criteria of the audit, and should provide…
Question
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure (Document reference ID: ISMS_L2_16, version 4). You review the document and notice a statement "Any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification". When interviewing staff, you found that there were differences in the understanding of the meaning of the phrase "weakness, event, and incident". The IT Security Manager explained that an online "information security handling" training seminar was conducted 6 months ago. All the people interviewed participated in and passed the reporting exercise and course assessment. You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.
Options
- ACollect more evidence on how areas subject to information security incidents are quarantined to
- BCollect more evidence on how information security incidents are reported via appropriate
- CCollect more evidence on how the organisation conducts information security incident training and
- DCollect more evidence on how the organisation learns from information security incidents and
- ECollect more evidence on how the organisation manages the Point of Contact (PoC) which
- FCollect more evidence on how the organisation tests the business continuity plan. (Relevant to
- GCollect more evidence on whether terms and definitions are contained in the information security
- HCollect more evidence to determine if ISO 27035 (Information security incident management) is
How the community answered
(47 responses)- A2% (1)
- B2% (1)
- C26% (12)
- D9% (4)
- E49% (23)
- F13% (6)
Explanation
These options are not valid audit trails because they are not directly related to the information security incident management process, which is the focus of the audit. The audit trails should be relevant to the objectives, scope, and criteria of the audit, and should provide sufficient and reliable evidence to support the audit findings and conclusions1. Option E is not valid because the PoC is not a part of the information security incident management process, but rather a role that is responsible for reporting and escalating information security incidents to the appropriate authorities2. The audit trail should focus on how the PoC performs this function, not how the organisation manages the PoC. Option G is not valid because the terms and definitions are not a part of the information security incident management process, but rather a part of the information security policy, which is a high- level document that defines the organisation's information security objectives, principles, and responsibilities3. The audit trail should focus on how the information security policy is communicated, implemented, and reviewed, not whether it contains terms and definitions. Option H is not valid because ISO 27035 is not a part of the information security incident management process, but rather a guidance document that provides best practices for managing information security incidents4. The audit trail should focus on how the organisation follows the requirements of ISO/IEC 27001:2022 for information security incident management, not whether it uses ISO 27035 as an internal audit criteria.
Topics
Community Discussion
No community discussion yet for this question.