nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #137

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. You are currently…

The correct answer is B. Determine whether any additional effective arrangements are in place to verify individual access. The best action to take in this scenario is to determine whether any additional effective arrangements are in place to verify individual access to secure areas, such as CCTV. This action is consistent with the audit principle of evidence-based approach, which requires the…

Physical and Environmental Security

Question

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. You are currently in a large room that is subdivided into several smaller rooms, each of which has a numeric combination lock and swipe card reader on the door. You notice two external contractors using a swipe card and combination number provided by the centre's reception desk to gain access to a client's suite to carry out authorised electrical repairs. You go to reception and ask to see the door access record for the client's suite. This indicates only one card was swiped. You ask the receptionist and they reply, "yes it's a common problem. We ask everyone to swipe their cards but with contractors especially, one tends to swipe and the rest simply 'tailgate' their way in" but we know who they are from the reception sign-in. Based on the scenario above which one of the following actions would you now take?

Options

  • ARaise an opportunity for improvement to have a large sign in reception reminding everyone
  • BDetermine whether any additional effective arrangements are in place to verify individual access
  • CRaise a nonconformity against control A.7.1 'security perimiters' as a secure area is not
  • DRaise a nonconformity against control A.7.6 'working in secure areas' as security measures for
  • ERaise a nonconformity against control A.5.20 'addressing information security in supplier
  • FRaise an opportunity for improvement that contractors must be accompanied at all times when

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    43% (20)
  • C
    7% (3)
  • D
    15% (7)
  • E
    4% (2)
  • F
    28% (13)

Explanation

The best action to take in this scenario is to determine whether any additional effective arrangements are in place to verify individual access to secure areas, such as CCTV. This action is consistent with the audit principle of evidence-based approach, which requires the auditor to obtain sufficient and appropriate audit evidence to support the audit findings and conclusions1. By verifying the existence and effectiveness of other security controls, the auditor can assess the extent and impact of the nonconformity observed, and determine the appropriate audit finding and

Topics

#physical security#contractor access#secure areas#audit evidence gathering

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice