nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #282

Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?

The correct answer is D. An auditor from an accreditation body E. An auditor trained in the CQI and IRCA scheme. Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. Accreditation Bodies: These…

Audit Types and Roles

Question

Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?

Options

  • AAn auditor certified by an auditor certification body
  • BAn auditor employed by a certification body
  • CAn auditor employed by an external consultancy organisation
  • DAn auditor from an accreditation body
  • EAn auditor trained in the CQI and IRCA scheme
  • FAn internal auditor from a customer

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    7% (2)
  • D
    90% (26)

Explanation

Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. Accreditation Bodies: These assess the competence of certification bodies but don't directly participate in second-party audits. CQI and IRCA: These organizations provide auditor certifications but their training alone doesn't automatically qualify someone for second-party ISO/IEC 27001 audits. The auditor should have specific knowledge of the standard.

Topics

#second-party audit#audit types#certification body#accreditation body

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice