ISO-IEC-27001-LEAD-AUDITOR · Question #187
The data centre at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit, several internal audits have been carried out by a…
The correct answer is A. Although the scope for each internal audit has been defined, there are no audit criteria defined for D. The audit programme does not reference audit methods or audit responsibilities. E. The audit programme does not take into account the relative importance of information security F. The audit programme does not take into account the results of previous audits. ISO/IEC 27001:2022 - Internal Audit Conformity Why A, D, E, F are correct concerns: ISO/IEC 27001:2022 Clause 9.2.2 explicitly mandates that the audit programme must: (a) define audit criteria and scope for each audit [→ A fails this], (b) include audit methods and…
Question
The data centre at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit, several internal audits have been carried out by a colleague working at another data centre within your Group. They secured their own ISO/IEC 27001:2022 certificate earlier in the year. You have just qualified as an Internal ISMS auditor and your manager has asked you to review the audit process and audit findings as a final check before the external Certification Body arrives. Which four of the following would cause you concern in respect of conformity to ISO/IEC 27001:2022 requirements?
Options
- AAlthough the scope for each internal audit has been defined, there are no audit criteria defined for
- BAudit reports are not held in hardcopy (i.e. on paper). They are only stored as *. PDF documents
- CThe audit process states the results of audits will be made available to 'relevant' managers, not
- DThe audit programme does not reference audit methods or audit responsibilities.
- EThe audit programme does not take into account the relative importance of information security
- FThe audit programme does not take into account the results of previous audits.
- GThe audit programme has not been signed as 'approved by Top Management.
- HThe audit programme shows management reviews taking place at irregular intervals during the
How the community answered
(41 responses)- A44% (18)
- B7% (3)
- C15% (6)
- G32% (13)
- H2% (1)
Explanation
ISO/IEC 27001:2022 - Internal Audit Conformity
Why A, D, E, F are correct concerns:
ISO/IEC 27001:2022 Clause 9.2.2 explicitly mandates that the audit programme must: (a) define audit criteria and scope for each audit [→ A fails this], (b) include audit methods and responsibilities [→ D fails this], and (c) take into account both the importance of the processes concerned [→ E fails this] and the results of previous audits [→ F fails this]. Each of these is a direct, testable requirement - omitting any one constitutes a non-conformity.
Why the distractors are wrong:
- B - The standard requires documented information as evidence but does not prescribe paper format; PDFs satisfy the requirement.
- C - "Relevant managers" is the exact wording in Clause 9.2.2(d); this is conformant, not a problem.
- G - There is no ISO 27001:2022 requirement for Top Management to formally sign or approve the audit programme.
- H - Clause 9.3 requires management reviews at "planned intervals," which need not be regular - irregular but planned intervals are acceptable, and management reviews are governed by a separate clause from the audit programme anyway.
Memory tip: Remember the four failures as "CMIR" - Criteria (A), Methods/responsibilities (D), Importance of processes (E), Results of previous audits (F) - these are the four things Clause 9.2.2 demands the audit programme explicitly address.
Topics
Community Discussion
No community discussion yet for this question.