nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #198

You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer require is processed…

The correct answer is C. Note the audit finding and check the process for dealing with incoming shipments relating to. Option C is correct because an auditor's primary role is to evaluate processes, not manage incidents or direct immediate fixes. The servers with exposed credentials are an observation - the auditor must now trace back to the underlying process for handling incoming ICT…

Asset Management and Media Disposal

Question

You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer require is processed by the organisation. It is either recommissioned and reused or is securely destroyed. You notice two servers on a bench in the corner of the room. Both have stickers on them with the server's name, IP address and admin password. You ask the ICT Manager about them, and he tells you they were part of a shipment received yesterday from a regular customer. Which one action should you take?

Options

  • AAsk the auditee to remove the labels, then carry on with the audit
  • BAsk the ICT Manager to record an information security incident and initiate the information
  • CNote the audit finding and check the process for dealing with incoming shipments relating to
  • DRaise a nonconformity against control 5.31 'Legal, staturary, regulatory and contractual
  • ERaise a nonconformity against control 8.20 'network security' (networks and network devices shall
  • FRecord what you have seen in your audit findings, but take no further action

How the community answered

(27 responses)
  • A
    7% (2)
  • C
    81% (22)
  • E
    7% (2)
  • F
    4% (1)

Explanation

Option C is correct because an auditor's primary role is to evaluate processes, not manage incidents or direct immediate fixes. The servers with exposed credentials are an observation - the auditor must now trace back to the underlying process for handling incoming ICT equipment to determine whether a systemic failure exists before drawing any conclusions.

Why the distractors fail:

  • A - Directing the auditee to remove labels oversteps the auditor's role; fixing symptoms isn't auditing, and it destroys evidence of a potential process gap.
  • B - Instructing the ICT Manager to raise an incident is also outside the auditor's remit; that's the auditee's responsibility to manage, not the auditor's to trigger.
  • D & E - Jumping straight to a named nonconformity (against 5.31 Legal requirements or 8.20 Network security) is premature without first examining the relevant process; you need evidence before citing a specific control failure.
  • F - Recording without further investigation is negligent; a responsible auditor must probe the process that allowed this situation to arise.

Memory tip: Think of the auditor as a detective, not a manager. Your job is to follow the evidence back to the process - "what procedure governs this, and was it followed?" - before labelling anything a nonconformity. If you catch yourself telling the auditee what to do, you've left audit mode.

Topics

#asset management#ICT media disposal#audit findings#information handling

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice