ISO-IEC-27001-LEAD-AUDITOR · Question #186
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external…
The correct answer is B. How access to source code and development tools are managed: This control requires the D. How protection against malware is implemented: This control requires the organisation to E. How the organisation evaluates its exposure to technical vulnerabilities: This control requires G. The organisation's arrangements for information deletion: This control requires the. The four controls from the list that the auditor in training should review are: organisation to restrict and monitor the access to the source code and development tools that are used to create, modify, or maintain the software applications and systems that process or store the…
Question
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the TECHNOLOGICAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.
Options
- AConfidentiality and nondisclosure agreements
- BHow access to source code and development tools are managed: This control requires the
- CHow power and data cables enter the building
- DHow protection against malware is implemented: This control requires the organisation to
- EHow the organisation evaluates its exposure to technical vulnerabilities: This control requires
- FInformation security awareness, education and training
- GThe organisation's arrangements for information deletion: This control requires the
- HThe organisation's business continuity arrangements
How the community answered
(29 responses)- A14% (4)
- B76% (22)
- C3% (1)
- H7% (2)
Explanation
The four controls from the list that the auditor in training should review are: organisation to restrict and monitor the access to the source code and development tools that are used to create, modify, or maintain the software applications and systems that process or store the data of external clients. This is important for ensuring the integrity, confidentiality, and availability of the software and the data, as well as for preventing unauthorized changes, errors, or malicious code injection. implement appropriate measures to detect, prevent, and remove malware from the IT systems and devices that process or store the data of external clients. This includes using antivirus software, firewalls, email filtering, web filtering, and other tools to protect against viruses, worms, ransomware, spyware, and other malicious software. This is essential for safeguarding the data and the systems from corruption, theft, or damage caused by malware. the organisation to identify and assess the technical vulnerabilities that may affect the IT systems and devices that process or store the data of external clients. This includes using vulnerability scanning tools, penetration testing tools, threat intelligence sources, and other methods to discover and evaluate the weaknesses and gaps in the security of the systems and the devices. This is necessary for prioritizing and implementing the appropriate corrective actions and controls to mitigate the risks posed by the vulnerabilities. organisation to establish and implement policies and procedures for deleting the data of external clients from the IT systems and devices when it is no longer needed or required. This includes defining the criteria and methods for data deletion, such as secure erasure, encryption, or physical destruction. This is important for complying with the contractual obligations and the legal and regulatory requirements regarding the retention and disposal of the data, as well as for protecting the confidentiality and integrity of the data.
Topics
Community Discussion
No community discussion yet for this question.