Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Exam ISO-IEC-27001-Lead-Auditor All Questions
Exam ISO-IEC-27001-Lead-Auditor All Questions

View all questions & answers for the ISO-IEC-27001-Lead-Auditor exam

PECB ISO 27001 ISO-IEC-27001-Lead-Auditor Question # 54 Topic 6 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 6 Question 54 Discussion:
Question #: 54
Topic #: 6

You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer require is processed by the organisation. It Is either recommissioned and reused or is securely destroyed.

You notice two servers on a bench in the corner of the room. Both have stickers on item with the server's name, IP address and admin password. You ask the ICT Manager about them, and he tells you they were part of a shipment received yesterday from a regular customer.

Which one action should you take?


A.

Ask the ICT Manager to record an information security incident and initiate the information security incident management process


B.

Note the audit finding and check the process for dealing with incoming shipments relating to customer IT security


C.

Record what you have seen in your audit findings, but take no further action


D.

Raise a nonconformity against control 5.31 Legal, staturary, regulatory and contractual requirements'


E.

Raise a nonconformity against control 8.20 'network security’ (networks and network devices shall be secured, managed and controlled to protect information in systems and applications)


F.

Ask the auditee to remove the labels, then carry on with the audit


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.