nerdexam
PECB

LEAD-AUDITOR · Question #126

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security of ABC's healthcare

The correct answer is A. Collect more evidence on how much residents' family members pay to install ABC's healthcare C. Collect more evidence to determine the number of users of ABC's healthcare mobile app. (relevant H. Collect more evidence to verify the developer's CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS. These options are either not relevant to the information security of ABC's healthcare mobile app development, support, and lifecycle process, or not within the scope of your audit. The amount of money that residents' family members pay to install the app (A) and the number of use

Conducting the Audit / Supplier Relationships

Question

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organisation outsourced the mobile app development to a professional software development organisation with CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified. The IT Manager presents the software security management procedure and summarises the process as follows:

The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum. The following security functions for personal data protection shall be available:

Access control. Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and Personal data pseudonymization. Vulnerability checked and no security backdoor You sample the latest Mobile App Test report - Reference ID: 0098, details as follows:

You would like to investigate other areas further to collect more audit evidence. Select three options that will not be in your audit trail.

Exhibit

LEAD-AUDITOR question #126 exhibit

Options

  • ACollect more evidence on how much residents' family members pay to install ABC's healthcare
  • BCollect more evidence by downloading and testing the mobile app on your phone. (Relevant to
  • CCollect more evidence to determine the number of users of ABC's healthcare mobile app. (relevant
  • DCollect more evidence on how the organisation performs testing of personal data handling.
  • ECollect more evidence on the organisation's business continuity policy. (Relevant to control A.5.30)
  • FCollect more evidence on how the organisation manages information security in the selection of an
  • GCollect more evidence on how the developer trains its product support personnel. (Relevant to
  • HCollect more evidence to verify the developer's CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS

How the community answered

(21 responses)
  • A
    52% (11)
  • D
    29% (6)
  • E
    5% (1)
  • F
    10% (2)
  • G
    5% (1)

Explanation

These options are either not relevant to the information security of ABC's healthcare mobile app development, support, and lifecycle process, or not within the scope of your audit. The amount of money that residents' family members pay to install the app (A) and the number of users of the app ?are not related to the information security aspects or objectives of the ISMS. The verification of the developer's certifications (H) is not your responsibility as an ISMS auditor, as you should rely on the competence and impartiality of the certification bodies that issued them.

Topics

#outsourced development#supply chain security#personal data handling#evidence collection

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice