nerdexam
PECB

LEAD-AUDITOR · Question #245

You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. Th

The correct answer is B. Collect more evidence on how and when the company pays the ransom fee to unlock the C. Collect more evidence on how and when the Human Resources manager pays the ransom fee to. Collect more evidence on how and when the Human Resources manager pays the ransom fee to unlock personal mobile data, i.e., credit card, and bank transfer. (Relevant to control A.5.26) This is not relevant to the audit of the organization's incident management process. The HR man

ISMS Audit Execution

Question

You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure and explains that the process is based on ISO/IEC 27035-1:2016. You review the document and notice a statement "any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification". When interviewing staff, you found that there were differences in the understanding of the meaning of "weakness, event, and incident". You sample incident report records from the event tracking system for the last 6 months with summarized results in the following table. You would like to further investigate other areas to collect more audit evidence. Select two options that will not be in your audit trail.

Exhibit

LEAD-AUDITOR question #245 exhibit

Options

  • ACollect more evidence by interviewing more staff about their understanding of the reporting
  • BCollect more evidence on how and when the company pays the ransom fee to unlock the
  • CCollect more evidence on how and when the Human Resources manager pays the ransom fee to
  • DCollect more evidence on how the organisation determined the incident recovery time. (Relevant to
  • ECollect more evidence on how the organization determined no further action was needed after the
  • FCollect more evidence on the incident recovery procedures. (Relevant to control A.5.26)

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    46% (19)
  • D
    27% (11)
  • E
    15% (6)
  • F
    5% (2)

Explanation

Collect more evidence on how and when the Human Resources manager pays the ransom fee to unlock personal mobile data, i.e., credit card, and bank transfer. (Relevant to control A.5.26) This is not relevant to the audit of the organization's incident management process. The HR manager's personal phone and how they handle a ransomware attack on it falls outside the scope of the ISMS audit. The organization is not responsible for personal devices. Collect more evidence on how and when the company pays the ransom fee to unlock the company's mobile phone and data, i.e., credit card, and bank transfer. (Relevant to control A.5.26) While seemingly relevant, this focuses on the method of payment for the ransom. The core issue is the organization paying the ransom at all, which is generally not best practice in incident response. The audit should focus on why this decision was made and if alternative solutions were considered (e.g., data backups, device wiping and restoration).

Topics

#incident management#ISO/IEC 27035#ransomware response#evidence collection

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice