Question 181

Which one of the following options describes the main purpose of a Stage 1 audit?
  • Question 182

    You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government offices. Parcels typically contain pharmaceutical products, biological samples, and documents such as passports and driving licences. You note that the company records show a very large number of returned items with causes including misaddressed labels and, in 15% of cases, two or more labels for different addresses for the one package. You are interviewing the Shipping Manager (SM).
    You: Are items checked before being dispatched?
    SM: Any obviously damaged items are removed by the duty staff before being dispatched, but the small profit margin makes it uneconomic to implement a formal checking process.
    You: What action is taken when items are returned?
    SM: Most of these contracts are relatively low value, therefore it has been decided that it is easier and more convenient to simply reprint the label and re-send individual parcels than it is to implement an investigation.
    You raise a nonconformity against ISO 27001:2022 based on the lack of control of the labelling process.
    At the closing meeting, the Shipping Manager issues an apology to you that his comments may have been misunderstood. He says that he did not realise that there is a background IT process that automatically checks that the right label goes onto the right parcel otherwise the parcel is ejected at labelling. He asks that you withdraw your nonconformity.
    Select three options of the correct responses that you as the audit team leader would make to the request of the Shipping Manager.
  • Question 183

    There is a network printer in the hallway of the company where you work. Many employees don't pick up their printouts immediately and leave them on the printer.
    What are the consequences of this to the reliability of the information?
  • Question 184

    As the Information Security Management System audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer.
    During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC 27001:2022.
    She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure.
    When the auditee was asked why there was a delay in removing access they replied, 'no one was available in the IT department during that period as a result of COVID-19.
    As soon as an IT officer became available the rights were removed.
    You note that she intends to raise a minor non-conformity against Access rights control (5.18). How should you respond to this?
  • Question 185

    An employee caught temporarily storing an MP3 file in his workstation will not receive an IR.