Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 4 Topic 1 Discussion

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 4 Topic 1 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 1 Question 4 Discussion:
Question #: 4
Topic #: 1

As the ISMS audit team leader, you are conducting a second-party audit of an international logistics organisation on behalf of an online retailer. During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Annex A of ISO/IEC 27001:2022. The control was justified in the Statement of Applicability. She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure.

Select the three most appropriate actions taken by the auditee to deal with this situation.


A.

Extend the required removal period from 24 hours to 7 days


B.

Change the process to ensure that leaver access protocols are removed before personnel leaves the premises


C.

Employee more IT personnel to ensure that the specified timescale can be met.


D.

Ensure that removing the server access protocols of leavers from senior management positions is prioritised


E.

Investigate whether the delays in removing access protocols caused any security breaches


F.

Monitor the ongoing process of removing leaver access protocols to determine whether it meets requirements


G.

Reprimand the IT team for failing to remove the access protocols in the required timescale


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.