nerdexam
PECB

LEAD-AUDITOR · Question #113

You are an experienced ISMS audit team leader providing guidance to an auditor in training. The auditor in training appears to be confused about the interpretation of competence in ISO 27001:2022 and

The correct answer is A. An employee recently transferred from the IT networks team to Software development was C. A new starter was unable to switch on CCTV monitoring because they had not been shown how to D. An IT technician failed to configure a new model of server correctly as a result of not reading the H. A senior manager could not assist in the organisation's information security incident recovery. These four scenarios are examples of a lack of competence, which is defined as the ability to apply the knowledge and skills needed to perform a work role or a task effectively and efficiently. Competence in ISO 27001:2022 is determined by the organisation's needs and expectation

Support - Competence

Question

You are an experienced ISMS audit team leader providing guidance to an auditor in training. The auditor in training appears to be confused about the interpretation of competence in ISO 27001:2022 and is seeking clarification from you that his understanding is correct. He sets out a series of mini scenarios and asks you which of these you would attribute to a lack of competence. Select four correct options.

Options

  • AAn employee recently transferred from the IT networks team to Software development was
  • BA senior programmer did not check their coding for errors as they were running late for a doctor's
  • CA new starter was unable to switch on CCTV monitoring because they had not been shown how to
  • DAn IT technician failed to configure a new model of server correctly as a result of not reading the
  • EAn experienced receptionist allowed a contractor she recognised to enter the data centre without
  • FA system administrator deleted two live accounts as well as five redundant accounts as a result of
  • GA data centre operator inadvertently placed a backup tape into an incorrect drive because they
  • HA senior manager could not assist in the organisation's information security incident recovery

How the community answered

(32 responses)
  • A
    59% (19)
  • B
    3% (1)
  • E
    6% (2)
  • F
    22% (7)
  • G
    9% (3)

Explanation

These four scenarios are examples of a lack of competence, which is defined as the ability to apply the knowledge and skills needed to perform a work role or a task effectively and efficiently. Competence in ISO 27001:2022 is determined by the organisation's needs and expectations, and it is based on the relevant education, training, or experience of the people involved in the ISMS. The organisation is required to ensure that all the people who affect the performance of the ISMS are competent, and to provide them with the necessary training and awareness to fulfil their roles and responsibilities. The four scenarios indicate that the people involved either lack the knowledge or skills to perform their tasks, or have not received the appropriate training or guidance to do so.

Topics

#competence#ISO 27001 clause 7.2#training and awareness#personnel competence

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice