nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #140

Which two of the following are valid audit conclusions?

The correct answer is D. The ISMS policy has been effectively communicated to the organisation E. The organisation's ISMS objectives meet the requirements of ISO/IEC 27001:2022. According to ISO 19011:2018, an audit conclusion is the outcome of an audit, provided by the audit team after considering the audit objectives and all audit findings1. An audit conclusion can be positive or negative, depending on whether the audit criteria are fulfilled or not…

Audit Reporting

Question

Which two of the following are valid audit conclusions?

Options

  • AISMS induction training does not provide guidance on malware prevention
  • BThe risk register had not been updated since June 202X
  • CCorrective action was outstanding for two internal audits
  • DThe ISMS policy has been effectively communicated to the organisation
  • EThe organisation's ISMS objectives meet the requirements of ISO/IEC 27001:2022
  • FThe schedule of applicability was based on the 2013 edition of ISO/IEC 27001, not the 2022

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    18% (6)
  • D
    67% (22)
  • F
    3% (1)

Explanation

According to ISO 19011:2018, an audit conclusion is the outcome of an audit, provided by the audit team after considering the audit objectives and all audit findings1. An audit conclusion can be positive or negative, depending on whether the audit criteria are fulfilled or not. An audit conclusion can also include recommendations for improvement or recognition of good practices. The statements D and E are valid audit conclusions, because they express the outcome of the audit based on the audit criteria and findings. For example: Statement D is a positive audit conclusion, because it indicates that the organisation has fulfilled the requirement of clause 5.2.2 of ISO/IEC 27001:2022, which states that the ISMS policy must be communicated within the organisation and to relevant interested parties2. The audit team must have obtained sufficient and appropriate audit evidence to support this conclusion, such as records of communication, awareness activities, feedback, etc. Statement E is a positive audit conclusion, because it indicates that the organisation has fulfilled the requirement of clause 6.2 of ISO/IEC 27001:2022, which states that the organisation must establish ISMS objectives that are consistent with the ISMS policy and relevant to the information security risks3. The audit team must have obtained sufficient and appropriate audit evidence to support this conclusion, such as records of objective setting, risk assessment, alignment with

Topics

#audit conclusions#audit findings distinction#ISMS effectiveness#audit report

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice