nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #118

Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the…

The correct answer is effectiveness; nonconformity; change; prevent. ISMS Audit Drag-and-Drop: Corrective Action Analysis Context This scenario involves ISO 27001 Clause 10.1 - Nonconformity and Corrective Action. The audit finding centers on ABC's failure to properly handle personal data (a GDPR/data protection violation), with complaints…

Conducting an Audit of an ISMS against ISO/IEC 27001

Question

Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the effectiveness of the continual improvement process. During the audit, you learned most of the residents' family members (90%) receive WeCare medical devices promotion advertisements through email and SMS once a week via ABC's healthcare mobile app. All of them do not agree on the use of the collected personal data for marketing or any other purposes than nursing and medical care on the signed service agreement with ABC. They have very strong reason to believe that ABC is leaking residents' and family members' personal information to a non-relevant third party and they have filed complaints. The Service Manager says that, after investigation, all these complaints have been treated as nonconformities. The corrective actions have been planned and implemented according to the nonconformity and corrective management procedure (Document reference ID: ISMS_L2_10.1, version 1). You write a nonconformity which you will follow up on later. Select the words that best complete the sentence:

Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #118 exhibit

Answer Area

Drag items

repairassuranceresponsibilityeffectivenessnonconformitypreventchangeproblem

Correct arrangement

  • effectiveness
  • nonconformity
  • change
  • prevent

Explanation

ISMS Audit Drag-and-Drop: Corrective Action Analysis

Context

This scenario involves ISO 27001 Clause 10.1 - Nonconformity and Corrective Action. The audit finding centers on ABC's failure to properly handle personal data (a GDPR/data protection violation), with complaints treated as nonconformities under procedure ISMS_L2_10.1.

The completed sentence reads approximately:

"ABC did not demonstrate the effectiveness of the corrective action taken for the nonconformity, nor did it change its processes to prevent recurrence."


Placement Breakdown

1. effectiveness ISO 27001:2022 Clause 10.1(d) explicitly requires the organization to "review the effectiveness of any corrective action taken." This is the auditor's primary concern - ABC claims corrective actions were implemented, but there is no evidence they actually worked. The auditor cannot confirm the complaints stopped or that data is no longer being leaked. effectiveness anchors the nonconformity statement.

2. nonconformity The complaints (unauthorized data sharing for marketing) were correctly classified as nonconformities per ABC's own procedure. This word identifies the subject of the corrective action. The clause structure follows: evaluate the effectiveness → of the corrective action → for the nonconformity. It ties the corrective action to the specific identified issue.

3. change ISO 27001:2022 Clause 10.1(f) requires the organization to "make changes to the ISMS, if necessary." Simply documenting a nonconformity is not enough - the underlying process (how personal data is shared with third parties) must be structurally changed. There is no evidence ABC changed its data-sharing practices or updated its controls.

4. prevent Corrective action's core purpose per Clause 10.1(b) is to eliminate the cause of the nonconformity "in order that it does not recur." prevent always closes the corrective action loop - without demonstrated prevention of recurrence, the corrective action is incomplete by definition.


Common Mistakes

Wrong choiceWhy it's wrong
repairImplies a quick fix; the standard requires root-cause elimination, not patching
assuranceQuality assurance concept; not part of ISO 27001 Clause 10.1 language
responsibilityRelevant to roles/ownership, but not the gap being described here
problemToo generic; ISO 27001 uses the precise term nonconformity, which has a defined meaning

Key Takeaway

The four correct words map directly to the ISO 27001 corrective action cycle: effectiveness (did it work?) → nonconformity (what was it for?) → change (was the system updated?) → prevent (will it recur?).

Topics

#continual improvement#corrective action#personal data protection#GDPR compliance

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice