These three characteristics are the fundamental properties of information security, as defined by the ISO/IEC 27000 standard, which provides the overview and vocabulary of information security, cybersecurity, and privacy protection12. They are also the basis for the information security objectives and controls of the ISO /IEC 27001 standard, which specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system34. The definitions of these characteristics are as follows12: *Availability: The property of being accessible and usable upon demand by an authorized entity. *Confidentiality: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes. *Integrity: The property of safeguarding the accuracy and completeness of information and processing methods. The other characteristics listed in the question, such as clarity, accessibility, completeness, importance, and efficiency, are not directly related to information security, although they may be relevant for other aspects of information management, such as quality, usability, or performance. References: = 1: ISO/IEC 27000:2022 Information technology - Security techniques - Information security, cybersecurity and privacy protection - Overview and vocabulary, clause 32: ISO/IEC 27000:2022 (en), Information security, cybersecurity and privacy protection - Overview and vocabulary13: ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, clause 6.24: ISO/IEC 27001:2022 (en), Information security, cybersecurity and privacy protection - Information security management systems - Requirements1
Question 187
下列哪一個是定性證據的例子?
Correct Answer: C
Qualitative evidence in an audit typically involves observations, interviews, and reviews that provide insights into the processes and compliance through subjective but informed assessments. An interview with information security personnel to validate compliance with the standard requirements is an example of qualitative evidence, where the quality and effectiveness of processes are assessed based on expert judgments rather than measurable metrics. References: PECB ISO/IEC 27001 Lead Auditor Course Material
* Minor Nonconformities: The identified nonconformities are minor, meaning they don't pose a significant risk to the information security management system (ISMS). They are likely to be easily rectified with focused corrective actions. * Opportunity for Improvement: This is not a nonconformity but a suggestion for enhancing the ISMS. It doesn't require immediate corrective action but should be addressed in the organization's continual improvement efforts. * Initial Certification: As this is an initial certification audit, the organization is expected to demonstrate its commitment to addressing any gaps identified. A partial audit allows for a focused follow-up on the specific areas of nonconformity, ensuring they have been adequately addressed. Why other options are not suitable: * A . Recommend certification after your approval of the proposed corrective action plan: While certification is the goal, it's premature to recommend it before verifying the effectiveness of the corrective actions. * B . Recommend that a full scope re-audit is required within 6 months: This is too extensive for minor nonconformities. A full re-audit is usually reserved for major nonconformities or systemic issues. * D . Recommend that the findings can be closed out at a surveillance audit in 1 year: This is too long a timeframe for addressing the nonconformities. Prompt corrective action is necessary to demonstrate commitment to the ISMS.
Question 189
問題: 當審計人員採用基於機率的抽樣方法進行事件日誌審查時,使用了哪種類型的抽樣方法?
Correct Answer: A
Comprehensive and Detailed In-Depth Explanation: * A. Correct answer: * Statistical sampling follows probability theory and ensures objective selection. * ISO 19011:2018 supports statistical sampling for unbiased audit conclusions. * B. Incorrect: * Judgment-based sampling is subjective, not probability-based. * C. Incorrect: * Multi-site sampling applies to organizations with multiple locations. Relevant Standard Reference: * ISO 19011:2018 Clause 6.4.9 (Using Statistical Sampling for Audits)