nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #172

After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include two additional…

The correct answer is D. Obtain information about the additional sites to inform the individual(s) managing the audit. According to the PECB Candidate Handbook for ISO/IEC 27001 Lead Auditor, the audit team leader should obtain information about the additional sites to inform the individual(s) managing the audit programme, as this may affect the audit objectives, scope, criteria, duration…

Audit Planning and Scope Management

Question

After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include two additional sites that have recently been acquired by the organisation. Considering this information, what action would you expect the audit team leader to take?

Options

  • AArrange to complete a remote Stage 1 audit of the two sites using a video conferencing
  • BIncrease the length of the Stage 2 audit to include the extra sites
  • CInform the auditee that the audit team leader accepts the request
  • DObtain information about the additional sites to inform the individual(s) managing the audit

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    19% (5)
  • D
    69% (18)

Explanation

According to the PECB Candidate Handbook for ISO/IEC 27001 Lead Auditor, the audit team leader should obtain information about the additional sites to inform the individual(s) managing the audit programme, as this may affect the audit objectives, scope, criteria, duration, resources, and risks. The audit team leader should also review the audit plan and make any necessary adjustments in consultation with the auditee and the audit client1.

Topics

#audit scope extension#Stage 1 audit#certification body#audit programme management

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice