The three options of the corrections and corrective actions listed that you would expect ABC to make in response to the nonconformity are: * B. ABC cancels the service agreement with WeCare. * E. ABC introduces background checks on information security performance for all suppliers. * F. ABC periodically monitors compliance with all applicable legislation and contractual requirements involving third parties. * B. This option is a possible correction and corrective action that ABC could take to address the nonconformity. A correction is the action taken to eliminate a detected nonconformity, while a corrective action is the action taken to eliminate the cause of a nonconformity and to prevent its recurrence1. By cancelling the service agreement with WeCare, ABC could stop the unauthorized use of residents' personal data and protect their privacy and rights. This could also prevent further complaints and legal issues from the residents and their family members. However, this option may also have some drawbacks, such as the loss of a service provider, the need to find an alternative solution, and the potential impact on the residents' well-being. * E. This option is a possible corrective action that ABC could take to address the nonconformity. By introducing background checks on information security performance for all suppliers, ABC could ensure that they select and work with reliable and trustworthy partners who respect the confidentiality, integrity, and availability of the information they handle. This could also help ABC to comply with information security control A.15.1.1 (Information security policy for supplier relationships), which requires the organisation to agree and document information security requirements for mitigating the risks associated with supplier access to the organisation's assets2. * F. This option is a possible corrective action that ABC could take to address the nonconformity. By periodically monitoring compliance with all applicable legislation and contractual requirements involving third parties, ABC could verify that the suppliers are fulfilling their obligations and responsibilities regarding information security. This could also help ABC to comply with information security control A.18.1.1 (Identification of applicable legislation and contractual requirements), which requires the organisation to identify, document, and keep up to date the relevant legislative, regulatory, contractual, and other requirements to which the organisation is subject3. References: 1: ISO 27000:2018 - Information technology - Security techniques - Information security management systems - Overview and vocabulary, clause 3.9 and 3.10 2: ISO/IEC 27001:2022 - Information technology - Security techniques - Information security management systems - Requirements, Annex A, control A. 15.1.1 3: ISO/IEC 27001:2022 - Information technology - Security techniques - Information security management systems - Requirements, Annex A, control A.18.1.1
Question 207
下列哪一個選項關於審計計畫是正確的?
Correct Answer: B
Comprehensive and Detailed In-Depth B . Correct Answer: Audit plans must remain flexible to adapt to unforeseen findings and risks. ISO 19011:2018 specifies that audit planning should allow dynamic adjustments. A . Incorrect: Audit procedures are part of execution, not planning. C . Incorrect: The audit team, not top management, prepares the audit plan. Relevant Standard Reference: ISO 19011:2018 Clause 5.4 (Audit Planning Flexibility)
The audit team primarily considered the objectivity of the evidence, making option B the correct answer. ISO 19011:2018 emphasizes that the reliability of audit evidence depends on several factors, including its objectivity, source, timing, and method of collection. Among these, objectivity is particularly important because it determines how free the evidence is from bias, interpretation, or subjective influence. In the scenario, the auditors explicitly compared evidence from surveillance cameras with photos and concluded that surveillance footage provided more objective proof. This comparison directly highlights objectivity as a key consideration. Surveillance footage records events continuously and without human intervention, reducing the risk of manipulation or selective representation. Photos, by contrast, can be staged, selectively captured, or taken out of context, making them less objective. The auditors also considered timing, such as transaction recording, which further supports objectivity by ensuring that events are recorded as they occur. While independence of the source is an important reliability factor, the scenario does not emphasize independence as the primary consideration. Instead, it focuses on how objective and trustworthy different forms of evidence are. Evidence collection techniques are also relevant, but the scenario describes the evaluation of evidence quality rather than how the evidence was gathered. Therefore, based on the explicit examples provided, objectivity of the evidence was the primary factor considered when evaluating reliability.
Question 210
您詢問 IT 經理,為什麼組織仍在使用行動應用程序,而個人資料加密和假名化測試卻失敗了。此外,服務經理是否有權批准測試。 IT經理解釋說,根據軟體安全管理程序,測試結果應由他批准。加密和假名功能失敗的原因是這些功能嚴重降低了系統和服務效能。需要額外 150% 的資源來滿足這一點。服務經理同意存取控制足夠好並且可以接受。這就是服務經理簽署批准書的原因。 您正在準備審計結果。選擇正確的選項。
Correct Answer: B
According to ISO 27001:2022 Annex A Control 8.30, the organisation shall ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. This includes developing and entering into licensing agreements that cover code ownership and intellectual property rights, and implementing appropriate contractual requirements related to secure design and coding in accordance with Annex A 8.25 and 8.2912 In this case, the organisation and the developer have performed security tests that failed, which indicates that the secure design and coding requirements of Annex A 8.29 were not met. The IT Manager explains that the encryption and pseudonymisation functions failed because they slowed down the system and service performance, and that an extra 150% of resources are needed to cover this. However, this does not justify the acceptance of the test results by the Service Manager, who is not authorised to approve the test according to the software security management procedure. The Service Manager should have consulted with the IT Manager, who is the owner of the process, and followed the procedure for handling nonconformities and corrective actions. The Service Manager's decision to continue the service based on access control alone exposes the organisation to the risk of compromising the confidentiality, integrity, and availability of personal data processed by the mobile app. Therefore, there is a nonconformity (NC) with clause 8.1, control A.8.30. References: 1: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Course by CQI and IRCA Certified Training 1 2: ISO/IEC 27001 Lead Auditor Training Course by PECB 2