nerdexam
PECB

LEAD-AUDITOR · Question #32

You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before being despatched to

The correct answer is B. Clause 8.1 - Operational planning and control. According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 8.1 requires an organization to plan, implement and control its processes needed to mee

ISO/IEC 27001 Requirements

Question

You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before being despatched to clients. You note that recently there has been a significant increase in the number of switches failing their initial configuration test and being returned for reprogramming. You ask the Chief Tester why and she says, 'It's a result of the recent ISMS upgrade'. Before the upgrade each technician had their own hard copy work instructions. Now, the eight members of my team have to share two laptops to access the clients' configuration instructions online. These delays put pressure on the technicians, resulting in more mistakes being made'. Based solely on the information above, which clause of ISO to raise a nonconformity against' Select one.

Options

  • AClause 7.5 - Documented information
  • BClause 8.1 - Operational planning and control
  • CClause 10.2 - Nonconformity and corrective action
  • DClause 7.3 - Awareness
  • EClause 7.2 - Competence
  • FClause 7.4 - Communication

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    74% (29)
  • C
    13% (5)
  • D
    3% (1)
  • F
    8% (3)

Explanation

According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 8.1 requires an organization to plan, implement and control its processes needed to meet ISMS requirements. This includes determining what needs to be done, how it will be done, who will do it, when it will be done, what resources are required, how performance will be evaluated, etc. Therefore, if an ISMS auditor conducting a third-party surveillance audit of a telecom's provider notes that there has been a significant increase in the number of switches failing their initial configuration test and being returned for reprogramming due to a recent ISMS upgrade that reduced access to work instructions, this indicates a nonconformity against clause 8.1 of ISO/IEC 27001:2022. The organization has failed to plan and control its operational processes effectively to ensure information security and quality.

Topics

#ISO 27001 Clause 8.1#operational planning and control#ISMS surveillance audit#documented information

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice