nerdexam
PECB

LEAD-AUDITOR · Question #200

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded…

The correct answer is C. No, audit scope should reflect all of the organization's divisions covered by the ISMS. No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.

Planning an ISO/IEC 27001 Audit

Question

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded the marketing division from the audit scope, although they stated in their ISMS scope that the whole company is included. Is this acceptable?

Options

  • AYes, audit and ISMS scope do not necessarily need to be the same
  • BNo, divisions that are not critical for the industrial sector in which the auditee operates can be
  • CNo, audit scope should reflect all of the organization's divisions covered by the ISMS

How the community answered

(29 responses)
  • A
    17% (5)
  • B
    10% (3)
  • C
    72% (21)

Explanation

No, the audit scope should reflect all of the organization's divisions that are covered by the ISMS. If the ISMS scope stated that it includes the whole company, the audit scope should align with this unless specifically justified and agreed upon by all stakeholders.

Topics

#audit scope#ISMS scope#certification scope#scope alignment

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice