ISO-IEC-27001-LEAD-AUDITOR · Question #65
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government…
The correct answer is B. 8.12 Data leakage protection. This is true because the auditee should have implemented D. 6.3 Information security awareness, education, and training. This is true because the auditee E. 7.10 Storage media. This is true because the auditee should have implemented controls to F. 8.3 Information access restriction. This is true because the auditee should have implemented I. 7.4 Physical security monitoring. This is true because the auditee should have implemented J. 5.13 Labelling of information. This is true because the auditee should have implemented. measures to prevent unauthorized disclosure of sensitive information, such as personal data, medical records, or official documents, that are contained in the parcels. Data leakage protection could include encryption, authentication, access control, logging, and monitoring of…
Question
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government offices. Parcels typically contain pharmaceutical products, biological samples, and documents such as passports and driving licences. You note that the company records show a very large number of returned items with causes including mis-addressed labels and, in 15% of company cases, two or more labels for different addresses for the one package. You are interviewing the Shipping Manager (SM). You: Are items checked before being dispatched? SH: Any obviously damaged items are removed by the duty staff before being dispatched, but the small profit margin makes it uneconomic to implement a formal checking process. You: What action is taken when items are returned? SM: Most of these contracts are relatively low value, therefore it has been decided that it is easier and more convenient to simply reprint the label and re-send individual parcels than it is to implement an investigation. You raise a nonconformity. Referencing the scenario, which six of the following Appendix A controls would you expect the auditee to have implemented when you conduct the follow-up audit?
Options
- A5.11 Return of assets
- B8.12 Data leakage protection. This is true because the auditee should have implemented
- C5.3 Segregation of duties
- D6.3 Information security awareness, education, and training. This is true because the auditee
- E7.10 Storage media. This is true because the auditee should have implemented controls to
- F8.3 Information access restriction. This is true because the auditee should have implemented
- G5.6 Contact with special interest groups
- H6.4 Disciplinary process
- I7.4 Physical security monitoring. This is true because the auditee should have implemented
- J5.13 Labelling of information. This is true because the auditee should have implemented
How the community answered
(21 responses)- A5% (1)
- B62% (13)
- C10% (2)
- G19% (4)
- H5% (1)
Explanation
measures to prevent unauthorized disclosure of sensitive information, such as personal data, medical records, or official documents, that are contained in the parcels. Data leakage protection could include encryption, authentication, access control, logging, and monitoring of data should have ensured that all employees and contractors involved in the shipping process are aware of the information security policies and procedures, and have received appropriate training on how to handle and protect the information assets in their custody. Information security awareness, education, and training could include induction programmes, periodic refreshers, awareness campaigns, e-learning modules, and feedback mechanisms13. protect the storage media that contain information assets from unauthorized access, misuse, theft, loss, or damage. Storage media could include paper documents, optical disks, magnetic tapes, flash drives, or hard disks14. Storage media controls could include physical locks, encryption, backup, disposal, or destruction14. controls to restrict access to information assets based on the principle of least privilege and the need-to-know basis. Information access restriction could include identification, authentication, authorization, accountability, and auditability of users and systems that access information controls to monitor the physical security of the premises where information assets are stored or processed. Physical security monitoring could include CCTV cameras, alarms, sensors, guards, or patrols16. Physical security monitoring could help detect and deter unauthorized physical access or intrusion attempts16. controls to label information assets according to their classification level and handling instructions. Labelling of information could include markings, tags, stamps, stickers, or barcodes1 . Labelling of information could help identify and protect information assets from unauthorized disclosure or misuse1 .
Topics
Community Discussion
No community discussion yet for this question.