nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #243

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded…

The correct answer is C. No, audit scope should reflect all of the organization's divisions covered by the ISMS. No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.

Planning an ISO/IEC 27001 Audit

Question

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded the marketing division from the audit scope, although they stated in their ISMS scope that the whole company is included. Is this acceptable?

Options

  • AYes, audit and ISMS scope do not necessarily need to be the same
  • BNo, divisions that are not critical for the industrial sector in which the auditee operates can be
  • CNo, audit scope should reflect all of the organization's divisions covered by the ISMS

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    18% (6)
  • C
    76% (25)

Explanation

No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.

Topics

#audit scope#ISMS scope#certification audit#scope alignment

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice