nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #174

You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of ABC's healthcare…

The correct answer is C. There is a nonconformity (NC). The Service Manager does not comply with the software security. Option C is correct because the software security management procedure explicitly states that the IT Manager is responsible for approving test results - yet it was the Service Manager who signed off. This is a procedural nonconformity regardless of the reasoning given, and the…

Audit Findings and Nonconformity Determination

Question

You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organization outsourced the mobile app development to a professional software development company with CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified. The IT Manager presented the software security management procedure and summarised the process as following:

The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum. The following security functions for personal data protection shall be available:

Access control. Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and Personal data pseudonymization. Vulnerability checked and no security backdoor You sample the latest Mobile App Test report, details as follows:

The IT Manager explains the test results should be approved by him according to the software security management procedure. The reason why the encryption and pseudonymisation functions failed is that these functions heavily slowed down the system and service performance. An extra 150% of resources are needed to cover this. The Service Manager agreed that access control is good enough and acceptable. That's why the Service Manager signed the approval. You are preparing the audit findings. Select the correct option.

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #174 exhibit

Options

  • AThere is a nonconformity (NC). The organisation and developer do not perform acceptance tests.
  • BThere is a nonconformity (NC). The organisation and developer perform security tests that fail.
  • CThere is a nonconformity (NC). The Service Manager does not comply with the software security
  • DThere is NO nonconformity (NC). The Service Manager makes a good decision to continue the

How the community answered

(44 responses)
  • A
    5% (2)
  • B
    20% (9)
  • C
    66% (29)
  • D
    9% (4)

Explanation

Option C is correct because the software security management procedure explicitly states that the IT Manager is responsible for approving test results - yet it was the Service Manager who signed off. This is a procedural nonconformity regardless of the reasoning given, and the approval was used to bypass mandatory security controls (AES-256 encryption and pseudonymization) that were defined as minimum requirements, not optional features subject to performance trade-offs.

Option A is wrong because acceptance/security testing was performed - the auditor even sampled the test report. The NC is not about the absence of testing.

Option B is wrong because failing security tests alone don't automatically constitute a nonconformity if proper risk acceptance processes are followed; the deeper problem here is who accepted the failure and whether that person had the authority to do so under the documented procedure.

Option D is wrong because a performance concern does not justify bypassing mandatory minimum security controls defined in the organization's own procedure - that decision required proper risk treatment documentation and the correct approver (IT Manager), not a unilateral call by the Service Manager.

Memory tip: In ISO 27001 audits, always ask two questions: Did the right person approve it? and Does the decision contradict a stated "minimum" requirement? If either answer is "no," you almost certainly have a nonconformity.

Topics

#nonconformity identification#software security management#supplier controls#Service Manager compliance

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice