nerdexam
PECB

LEAD-AUDITOR · Question #121

You are carrying out a third-party surveillance audit of a client's ISMS. You are currently in the secure storage area of the data centre where the organisation's customers are able to temporarily loc

The correct answer is B. Investigate whether pest infestation is an identified risk and if so, what risk treatment is to be C. Determine whether the high levels of rainfall have had other impacts on data centre operations e.g. F. Check with the guide that they intend to initiate the organisation's information security incident. The appropriate actions to take next are to investigate whether pest infestation is an identified risk and if so, what risk treatment is to be applied, to determine whether the high levels of rainfall have had other impacts on data centre operations, and to check with the guide t

Conducting the Audit / Physical and Environmental Security

Question

You are carrying out a third-party surveillance audit of a client's ISMS. You are currently in the secure storage area of the data centre where the organisation's customers are able to temporarily locate equipment coming into or going out of the site. The equipment is contained within locked cabinets and each cabinet is allocated to a single, specific client. Out of the corner of your eye you spot movement near the external door of the storage area. This is followed by a loud noise. You ask the guide what is going on. They tell you that recent high rainfall has raised local river levels and caused an infestation of rats. The noise was a specialist pest control stunning device being triggered. You check the device in the corner and find there is a large immobile rat contained within it. What three actions would be appropriate to take next?

Options

  • ATake no further action. This is an ISMS audit, not an environmental management system audit
  • BInvestigate whether pest infestation is an identified risk and if so, what risk treatment is to be
  • CDetermine whether the high levels of rainfall have had other impacts on data centre operations e.g.
  • DRaise a nonconformity against control 7.4 Physical Security monitoringusiness continuity
  • ERaise a nonconformity against control 7.2 Physical Entry
  • FCheck with the guide that they intend to initiate the organisation's information security incident
  • GInspect the client cabinets for signs of rodent ingress and record your findings as audit evidence
  • HAssist the guide in humanely disposing of the rat and reset the device

How the community answered

(63 responses)
  • A
    5% (3)
  • B
    54% (34)
  • D
    25% (16)
  • E
    11% (7)
  • G
    2% (1)
  • H
    3% (2)

Explanation

The appropriate actions to take next are to investigate whether pest infestation is an identified risk and if so, what risk treatment is to be applied, to determine whether the high levels of rainfall have had other impacts on data centre operations, and to check with the guide that they intend to initiate the organisation's information security incident process. These actions are relevant to the ISMS audit objectives and criteria, as they relate to the organisation's risk assessment and treatment, security performance, and incident management processes.

Topics

#physical security#risk treatment#incident management#business continuity

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice