PECB
LEAD-AUDITOR · Question #35
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external…
You've hit your limit · resets 4am (America/New_York)
ISO/IEC 27001 Controls
Question
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the TECHNOLOGICAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.
Options
- AThe development and maintenance of an information asset inventory
- BRules for transferring information within the organisation and to other organisations
- CConfidentiality and nondisclosure agreements
- DHow protection against malware is implemented
- EAccess to and from the loading bay
- FThe conducting of verification checks on personnel
- GRemote working arrangements
- HHow information security has been addressed within supplier agreements
- IHow the organisation evaluates its exposure to technical vulnerabilities
- JThe organisation's business continuity arrangements
Explanation
You've hit your limit · resets 4am (America/New_York)
Topics
#ISO 27001 Annex A#technological controls#Statement of Applicability#ISMS controls
Community Discussion
No community discussion yet for this question.