nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #90

You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit. Which two of the…

The correct answer is C. Verification should focus on whether any action undertaken is complete F. Verification should focus on whether any action undertaken has been undertaken effectively. According to ISO 27001:2022 clause 9.1.2, the organisation shall conduct internal audits at planned intervals to provide information on whether the information security management system conforms to the organisation's own requirements, the requirements of ISO 27001:2022, and is…

Audit Program Management

Question

You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit. Which two of the following statements are true?

Options

  • AVerification should focus on whether any action undertaken taken has been undertaken efficiently
  • BCorrections should be verified first, followed by corrective actions and finally opportunities for
  • CVerification should focus on whether any action undertaken is complete
  • DOpportunities for improvement should be verified first, followed by corrections and finally
  • ECorrective actions should be reviewed first, followed by corrections and finally opportunities for
  • FVerification should focus on whether any action undertaken has been undertaken effectively

How the community answered

(45 responses)
  • A
    7% (3)
  • C
    87% (39)
  • D
    2% (1)
  • E
    4% (2)

Explanation

According to ISO 27001:2022 clause 9.1.2, the organisation shall conduct internal audits at planned intervals to provide information on whether the information security management system conforms to the organisation's own requirements, the requirements of ISO 27001:2022, and is effectively implemented and maintained12 According to ISO 27001:2022 clause 10.1, the organisation shall react to the nonconformities and take action, as applicable, to control and correct them and deal with the consequences. The organisation shall also evaluate the need for action to eliminate the causes of nonconformities, in order to prevent recurrence or occurrence. The organisation shall implement any action needed, review the effectiveness of any corrective action taken, and make changes to the information security management system, if necessary12 A follow-up audit is a type of internal audit that is conducted after a previous audit to verify whether the nonconformities and corrective actions have been addressed and resolved, and whether the information security management system has been improved12 Therefore, the following statements are true for preparing a follow-up audit plan: Verification should focus on whether any action undertaken is complete. This means that the auditor should check whether the organisation has implemented all the planned actions to correct and prevent the nonconformities, and whether the actions have been documented and communicated as required12 Verification should focus on whether any action undertaken has been undertaken effectively. This means that the auditor should check whether the organisation has achieved the intended results and objectives of the actions, and whether the actions have eliminated or reduced the nonconformities and their causes and consequences12

Topics

#follow-up audit#corrective action verification#audit planning#audit effectiveness

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice