ISO-IEC-27001-LEAD-AUDITOR · Question #83
During a third-party certification audit, you are presented with a list of issues by an auditee. Which four of the following constitute 'internal' issues in the context of a management system to ISO…
The correct answer is C. Poor levels of staff competence as a result of cuts in training expenditure D. Poor morale as a result of staff holidays being reduced E. Increased absenteeism as a result of poor management G. A fall in productivity linked to outdated production equipment. According to ISO 27001:2022 clause 4.1, the organisation shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system (ISMS)12 External issues are…
Question
During a third-party certification audit, you are presented with a list of issues by an auditee. Which four of the following constitute 'internal' issues in the context of a management system to ISO 27001:2022?
Options
- AHigher labour costs as a result of an aging population
- BA rise in interest rates in response to high inflation
- CPoor levels of staff competence as a result of cuts in training expenditure
- DPoor morale as a result of staff holidays being reduced
- EIncreased absenteeism as a result of poor management
- FA reduction in grants as a result of a change in government policy
- GA fall in productivity linked to outdated production equipment
- HInability to source raw materials due to government sanctions
How the community answered
(19 responses)- C95% (18)
- F5% (1)
Explanation
According to ISO 27001:2022 clause 4.1, the organisation shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system (ISMS)12 External issues are factors outside the organisation that it cannot control, but can influence or adapt to. They include political, economic, social, technological, legal, and environmental factors that may affect the organisation's information security objectives, risks, and opportunities12 Internal issues are factors within the organisation that it can control or change. They include the organisation's structure, culture, values, policies, objectives, strategies, capabilities, resources, processes, activities, relationships, and performance that may affect the organisation's information security management system12 Therefore, the following issues are considered internal' in the context of a management system to ISO 27001:2022: Poor levels of staff competence as a result of cuts in training expenditure: This is an internal issue because it relates to the organisation's capability, resource, and process of developing and maintaining the competence of its personnel involved in the ISMS. The organisation can control or change its training expenditure and its impact on staff competence12 Poor morale as a result of staff holidays being reduced: This is an internal issue because it relates to the organisation's culture, value, and relationship with its employees. The organisation can control or change its staff holiday policy and its impact on staff morale12 Increased absenteeism as a result of poor management: This is an internal issue because it relates to the organisation's performance, structure, and accountability of its management. The organisation can control or change its management practices and its impact on staff absenteeism12 A fall in productivity linked to outdated production equipment: This is an internal issue because it relates to the organisation's capability, resource, and process of ensuring the availability and suitability of its production equipment. The organisation can control or change its equipment maintenance and upgrade and its impact on productivity12 The following issues are considered external' in the context of a management system to ISO 27001:2022:
Topics
Community Discussion
No community discussion yet for this question.