nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #86

You are an experienced ISMS audit team leader providing guidance to an ISMS auditor in training. They have been asked to carry out an assessment of external providers and have prepared a checklist…

The correct answer is A. I will check the other data centres are treated as external providers, even though they are part B. I will ensure external providers have a documented process in place to notify the organisation E. I will ensure the organisation is regularly monitoring, reviewing and evaluating external. of the same telecommunication group. This is appropriate because clause 8.1.4 of ISO 27001:2022 requires the organisation to ensure that externally provided processes, products or services that are relevant to the information security management system are controlled…

Supplier Relationships and External Providers

Question

You are an experienced ISMS audit team leader providing guidance to an ISMS auditor in training. They have been asked to carry out an assessment of external providers and have prepared a checklist containing the following activities. They have asked you to review their checklist to confirm that the actions they are proposing are appropriate. The audit they have been invited to participate in is a third-party surveillance audit of a data centre. The data centre agent is part of a wider telecommunication group. Each data centre within the group operates its own ISMS and holds its own certificate. Select three options that relate to ISO/IEC 27001:2022's requirements regarding external providers.

Options

  • AI will check the other data centres are treated as external providers, even though they are part
  • BI will ensure external providers have a documented process in place to notify the organisation
  • CI will ensure that the organisation has a reserve external provider for each process it has
  • DI will limit my audit activity to externally provided processes as there is no need to audit externally
  • EI will ensure the organisation is regularly monitoring, reviewing and evaluating external
  • FI will ensure the organization is has determined the need to communicate with external providers
  • GI will ensure that top management have assigned roles and responsibilities for those providing
  • HI will ensure that the organisation ranks its external providers and allocates the majority of its work

How the community answered

(37 responses)
  • A
    70% (26)
  • C
    8% (3)
  • D
    3% (1)
  • F
    16% (6)
  • G
    3% (1)

Explanation

of the same telecommunication group. This is appropriate because clause 8.1.4 of ISO 27001:2022 requires the organisation to ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. Externally provided processes, products or services are those that are provided by any external party, regardless of the degree of its relationship with the organisation. Therefore, the other data centres within the same telecommunication group should be treated as external providers and subject to the same controls as any other external provider12 of any risks arising from the use of its products or services. This is appropriate because clause 8.1.4 of ISO 27001:2022 requires the organisation to implement appropriate contractual requirements related to information security with external providers. One of the contractual requirements could be the obligation of the external provider to notify the organisation of any risks arising from the use of its products or services, such as security incidents, vulnerabilities, or changes that could affect the information security of the organisation. The external provider should have a documented process in place to ensure that such notification is timely, accurate, provider performance. This is appropriate because clause 8.1.4 of ISO 27001:2022 requires the organisation to monitor, review and evaluate the performance and effectiveness of the externally provided processes, products or services. The organisation should have a process in place to measure and verify the conformity and suitability of the external provider's deliverables and activities, and to provide feedback and improvement actions as necessary. The organisation should also maintain records of the monitoring, review and evaluation results12

Topics

#external providers#supplier management#audit checklist review#third-party audit

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice