ISO-IEC-27001-LEAD-AUDITOR · Question #133
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organisation's…
The correct answer is B. Justification is only required for any controls that the organisations choses to exclude D. The Statement of Applicability is owned and amended by the organisation's top management. B is false because ISO/IEC 27001 clause 6.1.3 requires justification for both included and excluded Annex A controls in the Statement of Applicability (SoA) - not just excluded ones. D is false because the SoA is owned and maintained by the information security function…
Question
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organisation's Statement of Applicability. Based on the requirements of ISO/IEC 27001, which two of the following observations about the Statement of Applicability are false?
Options
- AA Statement of Applicability must be produced by organisations seeking ISO/IEC 27001
- BJustification is only required for any controls that the organisations choses to exclude
- CJustification for both the inclusion and exclusion of Annex A controls in the Statement of
- DThe Statement of Applicability is owned and amended by the organisation's top management
- EAdditional controls not included in Appendix A may be added to the Statement of Applicability if
- FThe Statement of Applicability must include Organisational, Physical, People and Technological
How the community answered
(23 responses)- A4% (1)
- B52% (12)
- C13% (3)
- E26% (6)
- F4% (1)
Explanation
B is false because ISO/IEC 27001 clause 6.1.3 requires justification for both included and excluded Annex A controls in the Statement of Applicability (SoA) - not just excluded ones. D is false because the SoA is owned and maintained by the information security function (typically the ISMS manager), not top management; top management holds overall accountability for the ISMS but does not directly own or amend the SoA.
The remaining options are all true: A is correct because producing an SoA is a mandatory clause 6.1.3 requirement; C correctly states that justification covers both inclusions and exclusions; E is correct because organizations may add controls beyond Annex A if risk assessment identifies additional needs; and F is correct because ISO/IEC 27001:2022 Annex A is structured around four control themes - Organisational, People, Physical, and Technological.
Memory tip: Think "both ways, right person" - justification goes both ways (in and out), and the SoA belongs to the security team, not the boardroom.
Topics
Community Discussion
No community discussion yet for this question.