ISO-IEC-27001-LEAD-AUDITOR · Question #197
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team and the…
The correct answer is B. Make a note to ask the site maintenance manager for evidence that a fire extinguishing system E. Raise a nonconformity against control A.7.11 'supporting utilities' as information processing. B and E are correct because the label provides objective audit evidence that the gas-based fire suppression system is overdue for testing (12 months elapsed vs. a 6-month requirement). Option E is appropriate because ISO 27001 Annex A control A.7.11 'Supporting utilities'…
Question
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team and the organisation's guide. You request access to a locked room protected by a combination lock and iris scanner. The room contains several rows of uninterruptable power supplies along with several data cabinets containing client-supplied equipment, predominantly servers, and switches. You note that there is a gas-based fire extinguishing system in place. A label indicates that the system requires testing every 6 months however the most recent test recorded on the label was carried out by the manufacturer 12 months ago. Based on the scenario above which two of the following actions would you now take?
Options
- ADetermine if requirements for recording fire extinguisher checks have been revised within the last
- BMake a note to ask the site maintenance manager for evidence that a fire extinguishing system
- CProviding water-based extinguishers are accessible in the room, take no further action as these
- DRaise a nonconformity against control A.5.7 'threat intelligence' as the organisation has not
- ERaise a nonconformity against control A.7.11 'supporting utilities' as information processing
- FRequire the guide to initiate the organisation's information security incident process
How the community answered
(62 responses)- A10% (6)
- B69% (43)
- C3% (2)
- D2% (1)
- F16% (10)
Explanation
B and E are correct because the label provides objective audit evidence that the gas-based fire suppression system is overdue for testing (12 months elapsed vs. a 6-month requirement). Option E is appropriate because ISO 27001 Annex A control A.7.11 'Supporting utilities' directly covers the maintenance of equipment such as fire suppression systems that protect information processing facilities - a documented testing gap is a clear nonconformity. Option B is also correct audit practice: you note the finding and seek corroborating evidence from the site maintenance manager before closing the audit trail.
Why the distractors fail: A is irrelevant - the label's stated requirement is your baseline, and speculating about revised requirements without evidence is not sound audit practice. C is dangerous and wrong - water-based extinguishers are entirely unsuitable in a live electrical/server environment and would not remedy the maintenance nonconformity. D misapplies the control - A.5.7 covers threat intelligence gathering, not physical maintenance obligations. F overreacts - an overdue maintenance record is an audit finding, not an active information security incident requiring the incident response process.
Memory tip: Map the finding to the right Annex A domain first - anything that supports or physically protects information processing (power, cooling, fire suppression) lives in A.7.1x (Physical and Environmental Security). If the kit that keeps servers running isn't being maintained, that's A.7.11. Also remember: auditors document and seek evidence before concluding; they don't trigger incident processes for compliance gaps.
Topics
Community Discussion
No community discussion yet for this question.