Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 7 Question 73 Discussion

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services.The next step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organisation outsourced the mobile app development to a professional software development organisation with CMMI Level 5, ITSM(ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified.The IT Manager presents the software security management procedure and summarises the process as follows:The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum. The following security functions for personal data protection shall be available:Access control.Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; andPersonal data pseudonymization.Vulnerability checked and no security backdoorYou sample the latest Mobile App Test report - Reference ID: 0098, details as follows:You would like to investigate other areas further to collect more audit evidence. Select three options that will not be in your audit trail.
A) Collect more evidence on how much residents' family members pay to install ABC's healthcare mobile app. (Relevant to clause 4.2) and C) Collect more evidence to determine the number of users of ABC's healthcare mobile app. (relevant to clause 4.2) and H) Collect more evidence to verify the developer's CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certification. (Relevant to control A.5.21)
B) Collect more evidence by downloading and testing the mobile app on your phone. (Relevant to control A.8.1)
D) Collect more evidence on how the organisation performs testing of personal data handling. (Relevant to control A.5.34)
E) Collect more evidence on the organisation's business continuity policy. (Relevant to control A.5.30)
F) Collect more evidence on how the organisation manages information security in the selection of an external service provider. (Relevant to control A.5.19)
G) Collect more evidence on how the developer trains its product support personnel. (Relevant to clause 7.2)

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 7 Question 73 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 73
Topic #: 7
[All ISO-IEC-27001-Lead-Auditor Questions]

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services.

The next step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organisation outsourced the mobile app development to a professional software development organisation with CMMI Level 5, ITSM

(ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified.

The IT Manager presents the software security management procedure and summarises the process as follows:

The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum. The following security functions for personal data protection shall be available:

Access control.

Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and

Personal data pseudonymization.

Vulnerability checked and no security backdoor

You sample the latest Mobile App Test report - Reference ID: 0098, details as follows:

You would like to investigate other areas further to collect more audit evidence. Select three options that will not be in your audit trail.

Show Suggested Answer Hide Answer
Suggested Answer: A, C, H

The three options that will not be in your audit trail are A, C, and H. These options are either not relevant to the information security of ABC's healthcare mobile app development, support, and lifecycle process, or not within the scope of your audit. The amount of money that residents' family members pay to install the app (A) and the number of users of the app are not related to the information security aspects or objectives of the ISMS1. The verification of the developer's certifications (H) is not your responsibility as an ISMS auditor, as you should rely on the competence and impartiality of the certification bodies that issued them2. The other options are relevant and within the scope of your audit, as they relate to the security functions, testing, policies, and procedures of the mobile app development, support, and lifecycle process13. References: 1: ISO/IEC 27001:2022, Information technology --- Security techniques --- Information security management systems --- Requirements, Clause 4.2 n2: ISO/IEC 27006:2022, Information technology --- Security techniques --- Requirements for bodies providing audit and certification of information security management systems, Clause 4.1 n3: PECB Certified ISO/IEC 27001 Lead Auditor Exam Preparation Guide, Domain 5: Conducting an ISO/IEC 27001 audit


Contribute your Thoughts:

0/2000 characters
Aretha
1 day ago
Why do we care about family members' payments? Seems irrelevant.
upvoted 0 times
...
Tambra
6 days ago
Access control and encryption are a must!
upvoted 0 times
...
Truman
11 days ago
Wait, are they really following "security-by-design"?
upvoted 0 times
...
Ira
17 days ago
Definitely need to check the app testing process.
upvoted 0 times
...
Louann
22 days ago
CMMI Level 5 is impressive!
upvoted 0 times
...
Camellia
27 days ago
I think verifying the developer's certifications is essential, but I wonder if it falls under the right control for our audit objectives.
upvoted 0 times
...
Halina
1 month ago
I feel like understanding how the organization tests personal data handling is important, but I'm uncertain if it directly relates to the audit trail we need.
upvoted 0 times
...
Micah
1 month ago
I remember a similar practice question where we had to focus on technical controls, so I think downloading and testing the app could be crucial for assessing security.
upvoted 0 times
...
Tamie
1 month ago
I'm not entirely sure, but I think collecting evidence on how much residents' family members pay for the app might not be relevant to the security audit.
upvoted 0 times
...

Save Cancel