nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #190

You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the business continuity…

The correct answer is E. Collect more evidence on how the organisation makes sure all staff periodically conduct a G. Collect more evidence on how the organisation performs a business risk assessment to H. Collect more evidence on what resources the organisation provides to support the staff. According to ISO/IEC 27001:2022 clause 6.1, the organization must establish, implement and maintain an information security risk management process that includes the following activities: establishing and maintaining information security risk criteria; ensuring that repeated…

Business Continuity Management

Question

You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the business continuity management process. During the audit, you learned that the organisation activated one of the business continuity plans (BCPs) to make sure the nursing service continued during the recent pandemic. You ask the Service Manager to explain how the organization manages information security during the business continuity management process. The Service Manager presented the nursing service continuity plan for a pandemic and summarised the process as follows:

Stop the admission of any NEW residents. 70% of administration staff and 30% of medical staff will work from home. Regular staff self-testing, including submitting a negative test report 1 day BEFORE they come to the office. Install ABC's healthcare mobile app, tracking their footprint and presenting a GREEN Health Status QR-Code for checking on the spot. You ask the Service Manager how to prevent non-relevant family members or interested parties from accessing residents' personal data when staff work from home. The Service Manager cannot answer and suggests the IT Security Manager should help with that. You would like to further investigate other areas to collect more audit evidence. Select three options that will not be in your audit trail.

Options

  • ACollect more evidence on how information security protocols are maintained during disruption
  • BCollect more evidence that staff only use IT equipment protected from malware when working
  • CCollect more evidence by interviewing additional staff to ensure they are aware of the need to
  • DCollect more evidence on how and when the Business Continuity Plan has been tested. (Relevant
  • ECollect more evidence on how the organisation makes sure all staff periodically conduct a
  • FCollect more evidence on how the organisation manages information security on mobile devices
  • GCollect more evidence on how the organisation performs a business risk assessment to
  • HCollect more evidence on what resources the organisation provides to support the staff

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    17% (4)
  • C
    4% (1)
  • D
    8% (2)
  • E
    67% (16)

Explanation

According to ISO/IEC 27001:2022 clause 6.1, the organization must establish, implement and maintain an information security risk management process that includes the following activities: establishing and maintaining information security risk criteria; ensuring that repeated information security risk assessments produce consistent, valid and comparable results; identifying the information security risks; analyzing the information security risks; evaluating the information security risks; treating the information security risks; accepting the information security risks and the residual information security risks; communicating and consulting with stakeholders throughout the process; monitoring and reviewing the information security risks and the risk treatment plan. According to control A.5.29, the organization must establish, document, implement and maintain processes, procedures and controls to ensure the required level of continuity for information security during a disruptive situation. The organization must also: determine its requirements for information security and the continuity of information security management in adverse situations, e.g. during a crisis or disaster; establish, document, implement and maintain processes, procedures and controls to ensure the required level of continuity for information security during an adverse situation; verify the availability of information processing facilities. Therefore, the following options will not be in your audit trail, as they are not relevant to the information security risk management process or the information security continuity process: positive Covid test (Relevant to control A.7.2). This is not relevant to the information security aspects of business continuity management, as it is related to the health and safety of the staff, not the protection of information assets. Control A.7.2 is about screening of personnel prior to employment, not during employment. evaluate how fast the existing residents can be discharged from the nursing home. (Relevant to clause 6). This is not relevant to the information security aspects of business continuity management, as it is related to the operational and financial aspects of the business, not the identification and treatment of information security risks. Clause 6 is about the information security risk management process, not the business risk management process. working from home. (Relevant to clause 7.1). This is not relevant to the information security aspects of business continuity management, as it is related to the general provision of resources for the ISMS, not the specific processes, procedures and controls to ensure the continuity of information security during a disruptive situation. Clause 7.1 is about determining and providing the resources needed for the establishment, implementation, maintenance and continual improvement of the ISMS, not the resources needed for the staff working from home.

Topics

#business continuity#BCP testing#information security during disruption#mobile devices

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice