Exam ISO-IEC-27001-Lead-Auditor Topic 3 Question 284 Discussion
Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 284
Topic #: 3
Question #: 284
Topic #: 3
As an auditor, you have noticed that ABC Inc. has established a procedure to manage the removable storage medi a. The procedure is based on the classification scheme adopted by ABC Inc. Thus, if the information stored is classified as "confidential," the procedure applies. On the other hand, the information that is classified as "public," does not have confidentiality requirements: thus, only a procedure for ensuring its integrity and availability applies. What type of audit finding is this?
Suggested Answer: C Vote an answer
This scenario represents a conformity because ABC Inc. has implemented procedures for managing removable storage media that align with the classification scheme of the information stored. When information is classified as "confidential," more stringent procedures apply, whereas for "public" information, the procedures focus only on integrity and availability, following the organization's defined information classification policy.
by Marico at Jun 14, 2025, 07:34 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).