CEO는 회사의 상태와 회사의 미래 전략, CEO의 비전, 그리고 직원의 역할에 대한 자신의 견해를 담은 메일을 보냅니다. 메일은 다음과 같이 분류되어야 합니다.
정답: A
The mail sent by the CEO giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it should be classified as internal mail. Internal mail is a type of classification that indicates that the information is intended for internal use only, and should not be disclosed to external parties without authorization. The mail sent by the CEO contains information that is relevant and important for the employees of the company, but may not be suitable for public disclosure, as it may contain sensitive or confidential information about the company's performance, goals, or plans. References: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 34. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 37. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 14.
ISO-IEC-27001-Lead-Auditor-KR 문제 37
귀하는 교육 중인 감사원에게 지침을 제공하는 경험이 풍부한 ISMS 감사팀 리더입니다. 교육 중인 감사원은 ISO 27001:2022의 역량 해석에 대해 혼란스러워하는 듯하며, 그의 이해가 맞는지 귀하에게 명확히 해달라고 요청하고 있습니다. 그는 일련의 간단한 시나리오를 제시하고, 이 중 어느 것을 역량 부족으로 돌릴지 귀하에게 묻습니다. 올바른 옵션 4개를 선택하십시오.
정답: A,C,D,H
These four scenarios are examples of a lack of competence, which is defined as the ability to apply the knowledge and skills needed to perform a work role or a task effectively and efficiently12. Competence in ISO 27001:2022 is determined by the organisation's needs and expectations, and it is based on the relevant education, training, or experience of the people involved in the ISMS34. The organisation is required to ensure that all the people who affect the performance of the ISMS are competent, and to provide them with the necessary training and awareness to fulfil their roles and responsibilities35. The four scenarios indicate that the people involved either lack the knowledge or skills to perform their tasks, or have not received the appropriate training or guidance to do so. The other scenarios are not related to competence, but to other factors such as negligence, error, or policy violation. References: = 1: ISO 19011:2018 Guidelines for auditing management systems, clause 3.72: ISO/IEC 27007: 2011 Information technology - Security techniques - Guidelines for information security management systems auditing, clause 53: ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, clause 7.24: ISO 27001 Requirement 7.2 - Competence | ISMS.online15: ISO27001 Clause 7.2 Competence - Ultimate Certification Guide - High Table3
ISO-IEC-27001-Lead-Auditor-KR 문제 38
정답:
Explanation: An audit finding is the result of the evaluation of the collected audit evidence against audit criteria.
ISO-IEC-27001-Lead-Auditor-KR 문제 39
감사자로서, 귀하는 ABC Inc.가 이동식 저장 매체를 관리하는 절차를 수립했다는 것을 알아차렸습니다. 이 절차는 ABC Inc.에서 채택한 분류 체계에 기반합니다. 따라서 저장된 정보가 "기밀"로 분류된 경우 이 절차가 적용됩니다. 반면, "공개"로 분류된 정보에는 기밀 요구 사항이 없습니다. 따라서 무결성과 가용성을 보장하는 절차만 적용됩니다. 이는 어떤 유형의 감사 결과입니까?
정답: C
This scenario represents a conformity because ABC Inc. has implemented procedures for managing removable storage media that align with the classification scheme of the information stored. When information is classified as "confidential," more stringent procedures apply, whereas for "public" information, the procedures focus only on integrity and availability, following the organization's defined information classification policy. References: ISO/IEC 27001:2013, Clause A.8.2 (Information classification)
ISO-IEC-27001-Lead-Auditor-KR 문제 40
귀하는 감사팀 리더로서 첫 번째 제3자 ISMS 감시 감사를 수행하고 있습니다. 현재 귀하는 감사팀의 다른 멤버와 함께 감사 대상자의 데이터 센터에 있습니다. 당신은 현재 여러 개의 작은 방으로 세분화된 큰 방에 있으며, 각 방에는 숫자 조합 잠금 장치와 문에 스와이프 카드 판독기가 있습니다. 당신은 두 명의 외부 계약자가 센터 접수 데스크에서 제공한 스와이프 카드와 조합 번호를 사용하여 고객의 스위트룸에 접근하여 허가된 전기 수리를 수행하는 것을 보았습니다. 리셉션에 가서 고객 스위트의 출입 기록을 보여달라고 요청합니다. 이는 카드 한 장만 긁혔다는 것을 나타냅니다. 리셉션 담당자에게 물어보면 "네, 흔한 문제입니다. 저희는 모든 사람에게 카드를 긁으라고 요청하지만 특히 계약자의 경우 한 명은 긁고 나머지는 그냥 '꼬리만 대고' 들어오는 경향이 있습니다."라고 대답하지만 리셉션에서 서명을 통해 그들이 누구인지 알 수 있습니다. 위의 시나리오를 바탕으로, 이제 다음 중 어떤 조치를 취하시겠습니까?
정답: B
The best action to take in this scenario is to determine whether any additional effective arrangements are in place to verify individual access to secure areas, such as CCTV. This action is consistent with the audit principle of evidence-based approach, which requires the auditor to obtain sufficient and appropriate audit evidence to support the audit findings and conclusions1. By verifying the existence and effectiveness of other security controls, the auditor can assess the extent and impact of the nonconformity observed, and determine the appropriate audit finding and recommendation. The other options are not the best actions to take in this scenario, because they are either premature or inappropriate. For example: *Option A is inappropriate, because it is not the auditor's role to suggest specific solutions or improvements to the auditee, but rather to report the audit findings and recommendations based on the audit criteria and objectives2. A large sign in reception may not be an effective or feasible solution to address the issue of tailgating, and it may not reflect the root cause of the problem. *Option C is premature, because it assumes that the control A.7.1 'security perimeters' is not adequately implemented, without verifying the existence and effectiveness of other security controls that may compensate for the observed nonconformity. The auditor should not jump to conclusions based on a single observation, but rather gather sufficient and appropriate audit evidence to support the audit finding3. *Option D is premature, because it assumes that the control A.7.6 'working in secure areas' is not adequately implemented, without verifying the existence and effectiveness of other security controls that may compensate for the observed nonconformity. The auditor should not jump to conclusions based on a single observation, but rather gather sufficient and appropriate audit evidence to support the audit finding3. *Option E is inappropriate, because it is not related to the observed nonconformity, which is about the access control to secure areas, not the information security requirements agreed upon with the supplier. The auditor should not raise a nonconformity based on irrelevant or incorrect audit criteria4. *Option F is inappropriate, because it is not the auditor's role to suggest specific solutions or improvements to the auditee, but rather to report the audit findings and recommendations based on the audit criteria and objectives2. Requiring contractors to be accompanied at all times when accessing secure facilities may not be an effective or feasible solution to address the issue of tailgating, and it may not reflect the root cause of the problem. References: 1: ISO 19011:2018, 5.2; 2: ISO 19011:2018, 6.6; 3: ISO 19011:2018, 6.2; 4: ISO 19011:2018, 6.3; : ISO 19011:2018; : ISO 19011:2018; : ISO 19011:2018; : ISO 19011:2018