LEAD-AUDITOR · Question #259
LEAD-AUDITOR Question #259: Real Exam Question with Answer & Explanation
The correct answer is C. No, because it does not contain the justification for the exclusion of controls from Annex A of. The SoA must include justifications for excluding Annex A controls. The scenario states that the project team excluded certain controls but does not mention that justifications were documented. This violates ISO/IEC 27001 Clause 6.1.3 (Information Security Risk Treatment), which
Question
Options
- AYes, because it comprises an exhaustive list of controls considered applicable from Annex A of
- BNo, because security controls selected from sources other than Annex A of ISO/IEC 27001 are
- CNo, because it does not contain the justification for the exclusion of controls from Annex A of
Explanation
The SoA must include justifications for excluding Annex A controls. The scenario states that the project team excluded certain controls but does not mention that justifications were documented. This violates ISO/IEC 27001 Clause 6.1.3 (Information Security Risk Treatment), which requires documenting exclusions with reasons.
Community Discussion
No community discussion yet for this question.