ISO-IEC-27001-LEAD-AUDITOR · Question #200
As the Information Security Management System audit team leader, you are conducting a second- party audit of an international logistics company on behalf of an online retailer. During the audit, one…
The correct answer is A. Agree with the raising of a minor non-conformity but against control 5.15, not 5.18. Option A is correct because the 24-hour removal requirement is a policy rule governing when access is revoked upon departure - this falls under 5.15 (Access control), which establishes the organisation's access control rules and requirements. Control 5.18 (Access rights) covers…
Question
As the Information Security Management System audit team leader, you are conducting a second- party audit of an international logistics company on behalf of an online retailer. During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC 27001:2022. She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure. When the auditee was asked why there was a delay in removing access they replied, 'no one was available in the IT department during that period as a result of COVID-19. As soon as an IT officer became available the rights were removed. You note that she intends to raise a minor non-conformity against Access rights control (5.18). How should you respond to this?
Options
- AAgree with the raising of a minor non-conformity but against control 5.15, not 5.18.
- BAgree with the raising of the minor non-conformity against 5.18.
- CDisagree with the raising of a minor conformity as appropriate action was taken at the earliest
- DDisagree with the raising of the minor nonconformity as appropriate action was taken at the
- EDisagree with the raising of the minor nonconformity, there is sufficient evidence to justify an
- FRequire additional audit evidence to be obtained before determining whether a non-conformity is
How the community answered
(26 responses)- A58% (15)
- C4% (1)
- D12% (3)
- E4% (1)
- F23% (6)
Explanation
Option A is correct because the 24-hour removal requirement is a policy rule governing when access is revoked upon departure - this falls under 5.15 (Access control), which establishes the organisation's access control rules and requirements. Control 5.18 (Access rights) covers the provisioning, review, modification, and removal mechanisms, but it operates in accordance with the rules set by 5.15; the policy breach here is at the 5.15 level.
Why the distractors fail:
- B correctly identifies a minor nonconformity but cites the wrong control - 5.18 governs the mechanics, not the policy rule that was breached.
- C & D are wrong because COVID-19 is an explanation, not an exemption - the policy requirement was unmet for 20 employees over 3 months, so a nonconformity must be raised regardless of the cause.
- E is wrong because the circumstantial nature of the failure (single COVID-19-related period, rights removed as soon as possible) points to a minor, not major, nonconformity - a major would require systematic or complete absence of the control.
- F is wrong because there is already sufficient, clear evidence (20 cases, documented delays, auditee's own admission) to make a finding without further evidence.
Memory tip: Think of 5.15 as the rulebook (access control policy, including timing requirements) and 5.18 as the toolbox (how rights are provisioned/removed). When a policy rule is broken - like a deadline - cite the rulebook (5.15).
Topics
Community Discussion
No community discussion yet for this question.