ISO-IEC-27001-LEAD-AUDITOR · Question #50
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external…
Technological Controls in ISO 27001 Auditing The correct four are A, B, D, and G - information asset inventory, information transfer rules, malware protection, and remote working arrangements - because these represent controls implemented through IT systems, software, and…
Question
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the TECHNOLOGICAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.
Options
- AThe development and maintenance of an information asset inventory
- BRules for transferring information within the organisation and to other organisations
- CConfidentiality and nondisclosure agreements
- DHow protection against malware is implemented
- EAccess to and from the loading bay
- FThe conducting of verification checks on personnel
- GRemote working arrangements
- HHow information security has been addressed within supplier agreements
- JThe organisation's business continuity arrangements
Explanation
Technological Controls in ISO 27001 Auditing
The correct four are A, B, D, and G - information asset inventory, information transfer rules, malware protection, and remote working arrangements - because these represent controls implemented through IT systems, software, and technical infrastructure, which is what an auditor assigned to review technological controls would focus on in a data-storage organisation.
The five distractors each belong to a different control category: C (confidentiality/NDA agreements) and F (personnel verification) are people controls, rooted in HR and hiring processes; E (loading bay access) is a physical control concerned with premises security; H (supplier agreements) and J (business continuity arrangements) are organisational controls embedded in policy, planning, and contracts rather than in any technical system.
Memory tip: Sort controls into four "buckets" - Paper (organisational policies/contracts), People (HR/personnel), Physical (locks/doors/sites), and Tech (software/networks/systems). Anything you'd implement with code, a server, or an application goes in Tech; anything you'd sign, screen for, or physically restrict goes in one of the three P's.
Topics
Community Discussion
No community discussion yet for this question.