nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #151

You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organisation's…

The correct answer is A. Justification for both the inclusion and exclusion of Annex A controls in the Statement of D. A Statement of Applicability must be produced by organisations seeking ISO/IEC 27001. A is correct because ISO/IEC 27001 clause 6.1.3 explicitly requires the Statement of Applicability (SoA) to contain justification for both included and excluded Annex A controls - not just exclusions. D is correct because the SoA is mandatory documented information under clause…

ISMS Documentation

Question

You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organisation's Statement of Applicability. Based on the requirements of ISO/IEC 27001, which two of the following observations about the Statement of Applicability are true?

Options

  • AJustification for both the inclusion and exclusion of Annex A controls in the Statement of
  • BThe Statement of Applicability is owned and amended by the organisation's top management
  • CThe Statement of Applicability must be reviewed at least annually
  • DA Statement of Applicability must be produced by organisations seeking ISO/IEC 27001
  • EJustification is only required for any controls that the organisations choses to exclude
  • FThe Statement of Applicability must be reviewed at Management Review

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    3% (1)
  • C
    3% (1)
  • E
    6% (2)

Explanation

A is correct because ISO/IEC 27001 clause 6.1.3 explicitly requires the Statement of Applicability (SoA) to contain justification for both included and excluded Annex A controls - not just exclusions. D is correct because the SoA is mandatory documented information under clause 6.1.3; any organisation pursuing ISO/IEC 27001 certification must produce one, making it a non-negotiable artefact.

Why the distractors fail:

  • B is wrong - the standard does not assign ownership or amendment authority of the SoA to top management specifically; it is typically owned by the information security function.
  • C is wrong - the standard sets no minimum annual review cadence for the SoA; it must be kept current but no fixed frequency is mandated.
  • E is wrong - this is the opposite of A; justification is required for both inclusions and exclusions, not exclusions alone.
  • F is wrong - while Management Review (clause 9.3) covers the broader ISMS, the standard does not mandate the SoA be reviewed specifically at that meeting.

Memory tip: Think "SoA = mandatory + both ways." It is always mandatory for certification (D), and justification always goes both ways - in and out (A). If a distractor says "only exclusions" or implies the SoA is optional, it's wrong.

Topics

#Statement of Applicability#Annex A controls#ISO 27001 requirements#SoA content

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice