ISO-IEC-27001-LEAD-AUDITOR · Question #130
Drag and Drop Question You are an experienced ISMS audit team leader, assisting an auditor in training to write their first audit report. You want to check the auditor in training's understanding of…
The correct answer is This example relates to the use of audit criteria to determine conformity or nonconformity; This example relates to the identification of an audit finding; This description relates to the determination of an audit conclusion; This example relates to the collection of audit evidence. ISMS Audit Report Terminology - Drag-and-Drop Explained Core Concept This question tests knowledge of four distinct audit process terms defined in ISO 19011 (Guidelines for Auditing Management Systems). Each position represents a specific scenario/vignette; you must match the…
Question
Drag and Drop Question You are an experienced ISMS audit team leader, assisting an auditor in training to write their first audit report. You want to check the auditor in training's understanding of terminology relating to the contents of an audit report and chose to do this by presenting the following examples. For each example, you ask the auditor in training what the correct term is that describes the activity Match the activity to the description. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- This example relates to the use of audit criteria to determine conformity or nonconformity
- This example relates to the identification of an audit finding
- This description relates to the determination of an audit conclusion
- This example relates to the collection of audit evidence
Explanation
ISMS Audit Report Terminology - Drag-and-Drop Explained
Core Concept
This question tests knowledge of four distinct audit process terms defined in ISO 19011 (Guidelines for Auditing Management Systems). Each position represents a specific scenario/vignette; you must match the correct terminology label to it.
The four terms in logical process order are:
| Step | Term | What it means |
|---|---|---|
| 1 | Audit Evidence | Raw information collected (interviews, docs, observations) |
| 2 | Audit Criteria | The benchmark (policy/standard) used to judge evidence |
| 3 | Audit Finding | The result of comparing evidence against criteria |
| 4 | Audit Conclusion | The overall outcome after considering all findings |
Why Each Item Goes Where It Does
Position 1 → "Use of audit criteria to determine conformity or nonconformity"
The scenario at position 1 describes someone comparing collected evidence against a reference standard (e.g., "ISO 27001 clause 8.2 requires a risk assessment - the organization has one, therefore: conformity"). This is the definition of applying audit criteria. It is the evaluative act, not the data-gathering act.
Position 2 → "Identification of an audit finding"
An audit finding is the documented result of that evaluation - it records whether something conforms, doesn't conform, or presents an opportunity for improvement. The scenario here shows a specific, factual statement emerging from the criteria comparison (e.g., "Nonconformity: access reviews are not conducted at defined intervals per the organization's own policy").
Position 3 → "Determination of an audit conclusion"
A conclusion is the holistic judgement drawn after reviewing all findings collectively. The scenario at position 3 describes an auditor forming an overall opinion on the ISMS's effectiveness or suitability - not one single finding, but the sum of them. This always comes after findings are compiled.
Position 4 → "Collection of audit evidence"
The scenario here describes gathering raw information - sampling logs, interviewing staff, reviewing procedures, observing controls in action. Although evidence collection happens early in the real audit timeline, in this question the example appears at position 4 because the scenarios are not arranged chronologically - they are just four independent vignettes presented in the order the trainer chose.
Common Mistakes to Avoid
Confusing findings with conclusions. A finding is a specific, individual result (one nonconformity, one conformity). A conclusion is the aggregate verdict for the entire audit scope. Many trainees write conclusions where findings belong and vice versa.
Confusing evidence with findings. Evidence is raw and unevaluated (a screenshot, a log file, a staff statement). A finding is what you conclude after applying criteria to that evidence.
Assuming the positions are chronological. This is a matching exercise - the order the examples are presented does not reflect the order these steps occur in an audit. Don't let position 4 for "evidence collection" mislead you into thinking it happens last.
Treating criteria as criteria documents. Criteria are the reference requirements you audit against (ISO 27001 clauses, internal policies). Applying them means making a conformity judgement - it's an active comparison, not just citing a document.
Topics
Community Discussion
No community discussion yet for this question.
