Question 1 of 30
During an audit of a newly developed smart environmental sensor designed for residential use, an auditor is tasked with verifying compliance with ISO/IEC 27402:2023. The device collects ambient temperature, humidity, and occupancy data, which is transmitted to a cloud service for analysis and user access. The auditor discovers that the device\'s default firmware configuration retains raw sensor logs, including timestamps and unique device identifiers, for an indefinite period. What is the most critical finding an auditor must document regarding the device\'s adherence to the baseline requirements for data retention and minimization?
The device's default configuration retains raw sensor logs indefinitely, failing to implement a mechanism for automatic purging or anonymization of sensitive personal data as required by the standard.
The device transmits raw sensor logs to a cloud service without explicit user consent for data processing, which is a violation of privacy principles.
The device's firmware does not offer granular user controls for disabling specific sensor functions, limiting user autonomy over data collection.
The device's encryption protocols for data transmission are outdated, posing a risk to data confidentiality during transit.

Preparing for ISO/IEC 27402:2023 - IoT Security and Privacy Device Baseline Requirements Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free