PECB
LEAD-AUDITOR · Question #239
Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?
The correct answer is D. An auditor from an accreditation body E. An auditor trained in the CQI and IRCA scheme. Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. - Accreditation Bodies: These asses
Fundamental Concepts and Principles of an ISMS
Question
Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?
Options
- AAn auditor certified by an auditor certification body
- BAn auditor employed by a certification body
- CAn auditor employed by an external consultancy organisation
- DAn auditor from an accreditation body
- EAn auditor trained in the CQI and IRCA scheme
- FAn internal auditor from a customer
How the community answered
(47 responses)- A6% (3)
- B2% (1)
- C4% (2)
- D70% (33)
- F17% (8)
Explanation
- Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements. - Accreditation Bodies: These assess the competence of certification bodies but don't directly participate in second-party audits. - CQI and IRCA: These organizations provide auditor certifications but their training alone doesn't automatically qualify someone for second-party ISO/IEC 27001 audits. The auditor should have specific knowledge of the standard.
Topics
#second-party audit#audit types#auditor roles#accreditation body
Community Discussion
No community discussion yet for this question.