Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam ISO-IEC-27001-Lead-Auditor All Questions
Exam ISO-IEC-27001-Lead-Auditor All Questions

View all questions & answers for the ISO-IEC-27001-Lead-Auditor exam

PECB ISO 27001 ISO-IEC-27001-Lead-Auditor Question # 35 Topic 5 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 5 Question 35 Discussion:
Question #: 35
Topic #: 5

You are an experienced ISMS audit team leader providing guidance to an ISMS auditor in training. They have been asked to carry out an assessment of external providers and have prepared a checklist containing the following activities. They have asked you to review their checklist to confirm that the actions they are proposing are appropriate.

The audit they have been invited to participate in is a third-party surveillance audit of a data centre . The data centre agent is part of a wider telecommunication group. Each data centre within the group operates its own ISMS and holds its own certificate.

Select three options that relate to ISO/IEC 27001:2022's requirements regarding external providers.


A.

I will check the other data centres are treated as external providers, even though they are part of the same telecommunication group


B.

I will ensure external providers have a documented process in place to notify the organisation of any risks arising from the use of its products or services


C.

I will ensure that the organisation has a reserve external provider for each process it has identified as critical to preservation of the confidentiality, integrity and accessibility of its information


D.

I will limit my audit activity to externally provided processes as there is no need to audit externally provided products of services


E.

I will ensure the organization is regularly monitoring, reviewing and evaluating external provider performance


F.

I will ensure the organization is has determined the need to communicate with external providers regarding the ISMS


G.

I will ensure that top management have assigned roles and responsibilities for those providing external ISMS processes as well as internal ISMS processes


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.