nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #259

To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team verified a sample of server logs to determine if they can be edited or deleted. Which audit procedure was used?

The correct answer is A. Analysis. The audit procedure used here is "analysis." The audit team analyzed server logs to verify if they can be edited or deleted, focusing on evaluating the logs' properties and the controls over their manipulation to ensure they comply with ISO/IEC 27001 requirements.

Conducting an ISO/IEC 27001 Audit

Question

To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team verified a sample of server logs to determine if they can be edited or deleted. Which audit procedure was used?

Options

  • AAnalysis
  • BSampling
  • CObservation

How the community answered

(61 responses)
  • A
    70% (43)
  • B
    11% (7)
  • C
    18% (11)

Explanation

The audit procedure used here is "analysis." The audit team analyzed server logs to verify if they can be edited or deleted, focusing on evaluating the logs' properties and the controls over their manipulation to ensure they comply with ISO/IEC 27001 requirements.

Topics

#audit procedures#analysis#Annex A logging controls#evidence collection

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice