nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #196

You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before being despatched…

The correct answer is D. Clause 8.1 - Operational planning and control. Clause 8.1 is correct because it requires the organization to plan, implement, and control the processes needed to meet information security requirements - including ensuring adequate resources are in place. The ISMS upgrade changed the operational process (individual hard…

ISO 27001 Operational Requirements (Clause 8)

Question

You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before being despatched to clients. You note that recently there has been a significant increase in the number of switches failing their initial configuration test and being returned for reprogramming. You ask the Chief Tester why and she says, 'It's a result of the recent ISMS upgrade'. Before the upgrade each technician had their own hard copy work instructions. Now, the eight members of my team have to share two laptops to access the clients' configuration instructions online. These delays put pressure on the technicians, resulting in more mistakes being made'. Based solely on the information above, which clause of ISO/IEC 27001:2022 would be the most appropriate to raise a nonconformity against?

Options

  • AClause 10.2 - Nonconformity and corrective action
  • BClause 7.2 - Competence
  • CClause 7.5 - Documented information
  • DClause 8.1 - Operational planning and control

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    18% (7)
  • C
    3% (1)
  • D
    73% (29)

Explanation

Clause 8.1 is correct because it requires the organization to plan, implement, and control the processes needed to meet information security requirements - including ensuring adequate resources are in place. The ISMS upgrade changed the operational process (individual hard copies → shared online access) without provisioning sufficient resources (2 laptops for 8 technicians), directly causing operational failures. This is a breakdown in operational planning and control of that process.

Why the distractors are wrong:

  • A (Clause 10.2) covers how the organization responds to nonconformities with corrective action - it describes what happens after a problem is found, not the root cause of one. You don't raise a nonconformity against the clause that handles nonconformities.
  • B (Clause 7.2) addresses personnel competence (training, skills, qualifications). The technicians are competent - they're making mistakes because of resource constraints and time pressure, not lack of skill.
  • C (Clause 7.5) governs the control of documented information itself (creation, format, versioning). The configuration instructions still exist and are accessible; the problem is insufficient access due to too few laptops, not a documentation control failure.

Memory tip: Clause 8 = Operations. Whenever a process change within the ISMS fails to account for the resources or controls needed to execute that process reliably, think 8.1. Ask yourself: "Did they plan the operation properly?" If the answer is no, it's 8.1.

Topics

#Clause 8.1#operational planning and control#documented information#ISMS operational requirements

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice