Question 271

Which four of the following statements about audit reports are true?
  • Question 272

    Which two of the following phrases would apply to "plan" in relation to the Plan-Do-Check-Act cycle for a business process?
  • Question 273

    Which option below about the ISMS scope is correct?
  • Question 274

    You are an experienced audit team leader guiding an auditor in training.
    Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the TECHNOLOGICAL controls listed in the Statement of Applicability (SoA) and implemented at the site.
    Select four controls from the following that would you expect the auditor in training to review.
  • Question 275

    You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team.
    Your colleague seems unsure as to the difference between an information security event and an information security incident. You attempt to explain the difference by providing examples.
    Which three of the following scenarios can be defined as information security incidents?