nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #87

You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer require is processed…

The correct answer is B. Note the audit finding and check the process for dealing with incoming shipments relating to. According to ISO 27001:2022 clause 8.1.4, the organisation shall ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. This includes implementing appropriate contractual requirements…

Conducting an Audit

Question

You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer require is processed by the organisation. It Is either recommissioned and reused or is securely destroyed. You notice two servers on a bench in the corner of the room. Both have stickers on item with the server's name, IP address and admin password. You ask the ICT Manager about them, and he tells you they were part of a shipment received yesterday from a regular customer. Which one action should you take?

Options

  • AAsk the ICT Manager to record an information security incident and initiate the information
  • BNote the audit finding and check the process for dealing with incoming shipments relating to
  • CRecord what you have seen in your audit findings, but take no further action
  • DRaise a nonconformity against control 5.31 Legal, staturary, regulatory and contractual
  • ERaise a nonconformity against control 8.20 'network security' (networks and network devices shall
  • FAsk the auditee to remove the labels, then carry on with the audit

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    73% (27)
  • C
    5% (2)
  • D
    3% (1)
  • E
    14% (5)

Explanation

According to ISO 27001:2022 clause 8.1.4, the organisation shall ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. This includes implementing appropriate contractual requirements related to information security with external providers, such as customers who send ICT equipment for reclamation12 In this case, the organisation offers ICT reclamation services, which involves processing customer ICT equipment that may contain sensitive or confidential information. The organisation should have a process in place to ensure that the customer ICT equipment is handled securely and in accordance with the customer's information security requirements. The process should include steps such as verifying the customer's identity and authorisation, checking the inventory and condition of the equipment, removing or destroying any labels or stickers that contain information about the equipment or the customer, wiping or erasing any data stored on the equipment, and documenting the actions taken and the results achieved12 The fact that the auditor noticed two servers on a bench with stickers that reveal the server's name, IP address and admin password indicates that the process for dealing with incoming shipments relating to customer IT security is not effective or not followed. This could pose a risk of unauthorised access, disclosure, or modification of the customer's information or systems. Therefore, the auditor should note the audit finding and check the process for dealing with incoming shipments relating to customer IT security, and determine whether there is a nonconformity with clause 8.1.4 of ISO 27001:202212

Topics

#audit findings#asset management#physical security#auditor conduct

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice