ISO-IEC-27001-LEAD-AUDITOR · Question #118
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the…
The correct answer is effectiveness; nonconformity; change; prevent. ISMS Audit Drag-and-Drop: Corrective Action Analysis Context This scenario involves ISO 27001 Clause 10.1 - Nonconformity and Corrective Action. The audit finding centers on ABC's failure to properly handle personal data (a GDPR/data protection violation), with complaints…
Question
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the effectiveness of the continual improvement process. During the audit, you learned most of the residents' family members (90%) receive WeCare medical devices promotion advertisements through email and SMS once a week via ABC's healthcare mobile app. All of them do not agree on the use of the collected personal data for marketing or any other purposes than nursing and medical care on the signed service agreement with ABC. They have very strong reason to believe that ABC is leaking residents' and family members' personal information to a non-relevant third party and they have filed complaints. The Service Manager says that, after investigation, all these complaints have been treated as nonconformities. The corrective actions have been planned and implemented according to the nonconformity and corrective management procedure (Document reference ID: ISMS_L2_10.1, version 1). You write a nonconformity which you will follow up on later. Select the words that best complete the sentence:
Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- effectiveness
- nonconformity
- change
- prevent
Explanation
ISMS Audit Drag-and-Drop: Corrective Action Analysis
Context
This scenario involves ISO 27001 Clause 10.1 - Nonconformity and Corrective Action. The audit finding centers on ABC's failure to properly handle personal data (a GDPR/data protection violation), with complaints treated as nonconformities under procedure ISMS_L2_10.1.
The completed sentence reads approximately:
"ABC did not demonstrate the effectiveness of the corrective action taken for the nonconformity, nor did it change its processes to prevent recurrence."
Placement Breakdown
1. effectiveness
ISO 27001:2022 Clause 10.1(d) explicitly requires the organization to "review the effectiveness of any corrective action taken." This is the auditor's primary concern - ABC claims corrective actions were implemented, but there is no evidence they actually worked. The auditor cannot confirm the complaints stopped or that data is no longer being leaked. effectiveness anchors the nonconformity statement.
2. nonconformity
The complaints (unauthorized data sharing for marketing) were correctly classified as nonconformities per ABC's own procedure. This word identifies the subject of the corrective action. The clause structure follows: evaluate the effectiveness → of the corrective action → for the nonconformity. It ties the corrective action to the specific identified issue.
3. change
ISO 27001:2022 Clause 10.1(f) requires the organization to "make changes to the ISMS, if necessary." Simply documenting a nonconformity is not enough - the underlying process (how personal data is shared with third parties) must be structurally changed. There is no evidence ABC changed its data-sharing practices or updated its controls.
4. prevent
Corrective action's core purpose per Clause 10.1(b) is to eliminate the cause of the nonconformity "in order that it does not recur." prevent always closes the corrective action loop - without demonstrated prevention of recurrence, the corrective action is incomplete by definition.
Common Mistakes
| Wrong choice | Why it's wrong |
|---|---|
repair | Implies a quick fix; the standard requires root-cause elimination, not patching |
assurance | Quality assurance concept; not part of ISO 27001 Clause 10.1 language |
responsibility | Relevant to roles/ownership, but not the gap being described here |
problem | Too generic; ISO 27001 uses the precise term nonconformity, which has a defined meaning |
Key Takeaway
The four correct words map directly to the ISO 27001 corrective action cycle:
effectiveness (did it work?) → nonconformity (what was it for?) → change (was the system updated?) → prevent (will it recur?).
Topics
Community Discussion
No community discussion yet for this question.
