nerdexam
PECB

LEAD-AUDITOR · Question #133

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external…

The correct answer is B. Confidentiality and nondisclosure agreements C. How information security has been addressed within supplier agreements E. Rules for transferring information within the organisation and to other organisations F. The development and maintenance of an information asset inventory. According to the PECB Candidate Handbook for ISO/IEC 27001 Lead Auditor, the auditor in training should review the organisational controls that are related to the information security policy, the roles and responsibilities, the information classification, the information…

Auditing ISMS Controls (ISO/IEC 27001:2022)

Question

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the ORGANISATIONAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.

Options

  • AAccess to and from the loading bay
  • BConfidentiality and nondisclosure agreements
  • CHow information security has been addressed within supplier agreements
  • DHow power and data cables enter the building
  • ERules for transferring information within the organisation and to other organisations
  • FThe development and maintenance of an information asset inventory
  • GThe operation of the site CCTV and door control systems
  • HThe organisation's business continuity arrangements

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    71% (25)
  • D
    9% (3)
  • G
    14% (5)
  • H
    3% (1)

Explanation

According to the PECB Candidate Handbook for ISO/IEC 27001 Lead Auditor, the auditor in training should review the organisational controls that are related to the information security policy, the roles and responsibilities, the information classification, the information exchange, the supplier relationships, and the information asset management. These controls are aligned with the ISO/IEC 27001 requirements for clauses 5, 7, 8.2, 8.3, and 8.4.

Topics

#organizational controls#Statement of Applicability#ISO 27001:2022 control categories#ISMS audit

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice