nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #85

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their…

The correct answer is C. The auditee has identified the governmental authorities' needs and expectations on healthcare D. The auditee has identified the resident's needs and expectations on how they should protect the G. The IT service agreement with the data center where the artificial intelligence (AI) cloud server is. According to ISO 27001:2022 clause 4.3, the organisation shall determine the scope of the information security management system (ISMS) by considering the internal and external issues, the requirements of interested parties, and the interfaces and dependencies with other…

Context of the Organization

Question

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that the electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff. To verify the scope of ISMS, you interview the management system representative (MSR) who explains that the ISMS scope covers an outsourced data center. Select three options for the audit evidence you need to find to verify the scope of the ISMS.

Options

  • AThe auditee has identified the resident's needs and expectations on the facility and environmental
  • BThe auditee has ISO 9001 certification
  • CThe auditee has identified the governmental authorities' needs and expectations on healthcare
  • DThe auditee has identified the resident's needs and expectations on how they should protect the
  • EThe auditee has identified the resident's needs and expectations on the comfort facility, medical
  • FThe auditee has identified the resident's needs and expectations on healthcare medical treatment
  • GThe IT service agreement with the data center where the artificial intelligence (AI) cloud server is
  • HThe auditee is considering the purchase of a healthcare monitoring app from an external software

How the community answered

(36 responses)
  • A
    14% (5)
  • C
    72% (26)
  • E
    3% (1)
  • F
    8% (3)
  • H
    3% (1)

Explanation

According to ISO 27001:2022 clause 4.3, the organisation shall determine the scope of the information security management system (ISMS) by considering the internal and external issues, the requirements of interested parties, and the interfaces and dependencies with other organisations12 In this case, the ISMS scope covers an outsourced data center that hosts the artificial intelligence (AI) cloud server for healthcare monitoring and analysis of the residents' data. Therefore, the audit evidence you need to find to verify the scope of the ISMS should The auditee has identified the governmental authorities' needs and expectations on healthcare services and patient data handling. This is an external issue and an interested party requirement that affects the ISMS scope, as the auditee has to comply with the relevant laws and regulations regarding the quality, safety, and privacy of healthcare services and patient data12 The auditee has identified the resident's needs and expectations on how they should protect the resident's personal data. This is an external issue and an interested party requirement that affects the ISMS scope, as the auditee has to ensure the confidentiality, integrity, and availability of the resident's personal data that is collected, processed, and stored by the electronic wristband and the AI The IT service agreement with the data center where the artificial intelligence (AI) cloud server is located. This is an interface and dependency with another organisation that affects the ISMS scope, as the auditee has to control the externally provided processes, products, and services that are relevant to the ISMS, and to implement appropriate contractual requirements related to information security12

Topics

#ISMS scope#interested parties#outsourced services#healthcare personal data

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice