Question 41

What type of system ensures a coherent Information Security organisation?
  • Question 42

    Which of the following does an Asset Register contain? (Choose two)
  • Question 43

    You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure (Document reference ID:
    ISMS_L2_16, version 4).
    You review the document and notice a statement "Any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification". When interviewing staff, you found that there were differences in the understanding of the meaning of the phrase "weakness, event, and incident".
    The IT Security Manager explained that an online "information security handling" training seminar was conducted 6 months ago. All the people interviewed participated in and passed the reporting exercise and course assessment.
    You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.
  • Question 44

    You are conducting an ISMS audit. The next step in your audit plan is to verify that the organisation's information security risk treatment plan has been established and implemented properly. You decide to interview the IT security manager.
    You: Can you please explain how the organisation performs its information security risk assessment and treatment process?
    IT Security Manager: We follow the information security risk management procedure which generates a risk treatment plan.
    Narrator: You review risk treatment plan No. 123 relating to the planned installation of an electronic (invisible) fence to improve the physical security of the nursing home. You found the risk treatment plan was approved by IT Security Manager.
    You: Who is responsible for physical security risks?
    IT Security Manager: The Facility Manager is responsible for the physical security risk. The IT department helps them to monitor the alarm. The Facility Manager is authorized to approve the budget for risk treatment plan No. 123.
    You: What residual information security risks exist after risk treatment plan No. 123 was implemented?
    IT Security Manager: There is no information for the acceptance of residual information security risks as far as I know.
    You prepare your audit findings. Select three options for findings that are justified in the scenario.
  • Question 45

    Which six of the following actions are the individual(s) managing the audit programme responsible for?