ISO-IEC-27001-LEAD-AUDITOR · Question #64
Drag and Drop Question As the ISMS audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer. During the audit, one of your…
The correct answer is permissions; policy; rules; control. Explanation: ISO/IEC 27001:2022 Control 5.18 Nonconformity > Note: The actual sentence blanks aren't displayed in your question, but the correct arrangement (permissions → policy → rules → control) maps to a nonconformity statement that would read something like: > > "The…
Question
Drag and Drop Question As the ISMS audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer. During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC 27001:2022. She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure. Complete the sentence with the best word(s), dick on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- permissions
- policy
- rules
- control
Explanation
Explanation: ISO/IEC 27001:2022 Control 5.18 Nonconformity
Note: The actual sentence blanks aren't displayed in your question, but the correct arrangement (permissions → policy → rules → control) maps to a nonconformity statement that would read something like:
"The organization failed to revoke user [permissions] in accordance with the [policy], which defines the [rules] for implementing the access rights [control]."
Item-by-Item Breakdown
1. permissions (Blank 1)
The first blank describes what was not removed - the specific server access permissions of the 20 departed employees. This is the concrete, technical thing that was missing: not abstract "rights" conceptually, but the actual configured permissions in the system. "Rights" is a distractor - while control 5.18 is called "Access rights," the thing being provisioned or revoked at the system level is permissions.
2. policy (Blank 2)
The second blank refers to the organization's documented policy - specifically the one that stated access must be removed within 24 hours of departure. A policy is a high-level, management-approved statement of intent. The 24-hour requirement came from a policy, not a process or a control. The nonconformity exists precisely because reality (1 week) contradicted the policy requirement.
3. rules (Blank 3)
The third blank refers to the rules - the specific, actionable statements within or derived from the policy that govern how access removal must happen. Rules are more granular than policy but less procedural than a process. This distinguishes the what is required (rules) from the how it is done (process).
4. control (Blank 4)
The final blank anchors the finding to Annex A control 5.18. In ISO 27001 terminology, a "control" is a specific measure from Annex A selected to treat a risk. The nonconformity is documented against this specific control, not loosely against "guidance" or "options."
Common Mistakes & Misconceptions
| Distractor | Why It's Wrong Here |
|---|---|
rights | Control 5.18 is named "Access rights," so it's tempting - but at the system level, you revoke permissions, not abstract rights |
process | A process describes how something is done procedurally; the 24-hour rule is a policy requirement, not a process step |
guidance | Guidance is advisory/non-mandatory; a 24-hour removal requirement is mandatory, making it a policy |
options | Has no meaningful place in an audit nonconformity statement |
Key Takeaway
The hierarchy matters: permissions (the technical artifact) → policy (the mandate) → rules (the specific requirements) → control (the ISO 27001 Annex A reference). This mirrors how audit nonconformities are structured: what failed → against what requirement → under what standard.
Topics
Community Discussion
No community discussion yet for this question.
