ISO-IEC-27001-LEAD-AUDITOR · Question #243
AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded…
The correct answer is C. No, audit scope should reflect all of the organization's divisions covered by the ISMS. No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.
Question
AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded the marketing division from the audit scope, although they stated in their ISMS scope that the whole company is included. Is this acceptable?
Options
- AYes, audit and ISMS scope do not necessarily need to be the same
- BNo, divisions that are not critical for the industrial sector in which the auditee operates can be
- CNo, audit scope should reflect all of the organization's divisions covered by the ISMS
How the community answered
(33 responses)- A6% (2)
- B18% (6)
- C76% (25)
Explanation
No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.
Topics
Community Discussion
No community discussion yet for this question.