nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #246

The auditor should consider (1)-------when determining the (2)--------

The correct answer is B. (1) Audit risks, (2) audit objectives. The auditor should consider "audit risks" when determining the "audit objectives." Understanding the risks associated with the audit helps define the objectives clearly, ensuring that the audit focuses on the most significant areas of concern, aligns with the audit scope, and…

Planning an ISO/IEC 27001 Audit

Question

The auditor should consider (1)-------when determining the (2)--------

Options

  • A(1) Standard requirements. (2) audit criteria
  • B(1) Audit risks, (2) audit objectives
  • C(1) Penalties related to legal noncompliance, (2) materiality

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • C
    3% (1)

Explanation

The auditor should consider "audit risks" when determining the "audit objectives." Understanding the risks associated with the audit helps define the objectives clearly, ensuring that the audit focuses on the most significant areas of concern, aligns with the audit scope, and adequately addresses the risks identified.

Topics

#audit risks#audit objectives#audit planning#risk consideration

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice