nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #51

You are preparing the audit findings. Select two options that are correct.

The correct answer is A. There is an opportunity for improvement (OFI). The iLiirmation security incident training D. There is a nonconformity (NC). Based on sampling interview results, none of the interviewees. According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 7.2 requires an organization to determine the necessary competence of persons doing…

Audit Findings and Conclusions

Question

You are preparing the audit findings. Select two options that are correct.

Options

  • AThere is an opportunity for improvement (OFI). The iLiirmation security incident training
  • BThere is no nonconformance. The information security weaknesses, events, and incidents are
  • CThere is no nonconformance. The information security handling training has performed, and its
  • DThere is a nonconformity (NC). Based on sampling interview results, none of the interviewees
  • EThere is a nonconformity (NC). The information security incident training has failed. This is not
  • FThere is an opportunity for improvement (OFI). The information security weaknesses, events, and

How the community answered

(30 responses)
  • A
    63% (19)
  • B
    20% (6)
  • C
    3% (1)
  • E
    3% (1)
  • F
    10% (3)

Explanation

According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 7.2 requires an organization to determine the necessary competence of persons doing work under its control that affects its ISMS performance, and to provide training or take other actions to acquire or maintain the necessary competence1. Control A.6.3 requires an organization to ensure that all employees and contractors are aware of information security threats and concerns, their responsibilities and liabilities, and are equipped to support organizational policies and procedures in this respect2. Therefore, if an ISMS auditor finds that the information security incident training effectiveness can be improved, this indicates an opportunity for improvement (OFI) that is relevant to clause 7.2 and control A.6.3. According to ISO/IEC 27001:2022, clause 9.1 requires an organization to monitor, measure, analyze and evaluate its ISMS performance and effectiveness1. Control A.5.24 requires an organization to define and apply procedures for reporting information security events and weaknesses2. Therefore, if an ISMS auditor finds that based on sampling interview results, none of the interviewees were able to describe the incident management procedure reporting process including the role and responsibilities of personnel, this indicates a nonconformity (NC) that is not conforming with clause 9.1 and control A.5.24.

Topics

#audit findings classification#nonconformity vs OFI#incident training#audit conclusions

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice