ISO-IEC-27001-LEAD-AUDITOR · Question #115
You are an experienced ISMS audit team leader providing guidance to an auditor in training. She asks you why it is important to have specific criteria relating to the grading of nonconformities…
The correct answer is A. Because grading criteria provide a common basis for the evaluation of nonconformities across the. The correct response is A, because grading criteria provide a common basis for the evaluation of nonconformities across the organization. Grading criteria are the rules or standards that define the severity or impact of nonconformities, and help to determine the appropriate…
Question
You are an experienced ISMS audit team leader providing guidance to an auditor in training. She asks you why it is important to have specific criteria relating to the grading of nonconformities. Which one of the following responses is correct?
Options
- ABecause grading criteria provide a common basis for the evaluation of nonconformities across the
- BBecause ISO/IEC 27001:2022 requires it
- CBecause the establishment and implementation of grading criteria demonstrate a high level of
- DBecause grading criteria will ensure that all auditors score nonconformities in exactly the same
How the community answered
(31 responses)- A87% (27)
- B3% (1)
- C3% (1)
- D6% (2)
Explanation
The correct response is A, because grading criteria provide a common basis for the evaluation of nonconformities across the organization. Grading criteria are the rules or standards that define the severity or impact of nonconformities, and help to determine the appropriate corrective actions and follow-up activities. Grading criteria are important for several reasons, such as: They ensure consistency and objectivity in the assessment and reporting of nonconformities, and avoid subjective or arbitrary judgments. They facilitate the communication and understanding of nonconformities among the auditors, the auditees, and the audit clients, and enable the comparison and benchmarking of nonconformities across different processes, functions, or locations. They support the prioritization and allocation of resources for the resolution of nonconformities, and the monitoring and measurement of the effectiveness of the corrective actions. They demonstrate the commitment and accountability of the organization to the continual improvement of the ISMS, and the compliance with the ISMS requirements and expectations.
Topics
Community Discussion
No community discussion yet for this question.