nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #119

You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and included all the…

The correct answer is B. This response is correct because the audit team leader should document the request of the D. This response is correct because the audit team leader should not withdraw the nonconformity H. This response is correct because the audit team leader should state that a follow up audit will. The three options of the correct responses of an audit team leader to the request of the Technical Technical Director and include it in the audit report, along with the audit findings and conclusions12. This will ensure transparency and traceability of the audit process and the…

Audit Reporting, Conclusion and Follow-up

Question

You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and included all the information security controls in ISO/IEC 27001:2022 Appendix A in their Statement of Applicability. During the Stage 2 audit, your audit team found that there was no evidence of a risk treatment plan for the implementation of the three controls (5.3 Segregation of duties, 6.1 Screening, 7.12 Cabling security). You raise a nonconformity against clause 6.1.3.e of ISO 27001:2022. At the closing meeting, the Technical Director issues an extract from an amended Statement of Applicability (as shown) and asks for the nonconformity to be withdrawn. Select three options of the correct responses of an audit team leader to the request of the Technical Director.

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #119 exhibit

Options

  • AAdvise management that the information provided will be reviewed when the auditors have more
  • BThis response is correct because the audit team leader should document the request of the
  • CAdvise the Technical Director that once a nonconformity is raised it cannot be withdrawn.
  • DThis response is correct because the audit team leader should not withdraw the nonconformity
  • EAsk the auditor who raised the issue for their opinion on how you should respond to the request.
  • FInform the Technical Director that the nonconformity will be changed to an Opportunity for
  • GReview the documentation produced and withdraw the nonconformity.
  • HThis response is correct because the audit team leader should state that a follow up audit will

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    64% (18)
  • C
    4% (1)
  • E
    4% (1)
  • F
    18% (5)

Explanation

The three options of the correct responses of an audit team leader to the request of the Technical Technical Director and include it in the audit report, along with the audit findings and conclusions12. This will ensure transparency and traceability of the audit process and the audit based on the amended Statement of Applicability alone. The nonconformity was raised against clause 6.1.3.e of ISO 27001:2022, which requires the organisation to produce and maintain a risk treatment plan that defines how the information security risks are treated, including the controls selected and their implementation status34. The Statement of Applicability is only one part of the risk treatment plan, and it does not provide sufficient evidence that the controls have been implemented effectively. The audit team leader should base the nonconformity on the objective evidence obtained during the audit, not on the subjective claims of the auditee12. be necessary to review the evidence for the updated Statement of Applicability. A follow up audit is an audit that is conducted after a previous audit to verify the implementation and effectiveness of the corrective actions and/or opportunities for improvement that were agreed upon as a result of the previous audit56. The follow up audit should seek to ensure that the nonconformity has been effectively addressed and that the ISMS is compliant and effective. The follow up audit should also consider any new or changed risks or requirements that may affect the ISMS56.

Topics

#risk treatment plan#Statement of Applicability#nonconformity withdrawal#closing meeting conduct

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice