nerdexam
PECB

LEAD-AUDITOR · Question #239

Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?

The correct answer is D. An auditor from an accreditation body E. An auditor trained in the CQI and IRCA scheme. Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. - Accreditation Bodies: These asses

Fundamental Concepts and Principles of an ISMS

Question

Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?

Options

  • AAn auditor certified by an auditor certification body
  • BAn auditor employed by a certification body
  • CAn auditor employed by an external consultancy organisation
  • DAn auditor from an accreditation body
  • EAn auditor trained in the CQI and IRCA scheme
  • FAn internal auditor from a customer

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    4% (2)
  • D
    70% (33)
  • F
    17% (8)

Explanation

  • Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. - Accreditation Bodies: These assess the competence of certification bodies but don't directly participate in second-party audits. - CQI and IRCA: These organizations provide auditor certifications but their training alone doesn't automatically qualify someone for second-party ISO/IEC 27001 audits. The auditor should have specific knowledge of the standard.

Topics

#second-party audit#audit types#auditor roles#accreditation body

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice