nerdexam
PECB

LEAD-AUDITOR · Question #326

Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the…

The correct answer is review; Management Review; assess; regular; suitability. Explanation: Check Stage of PDCA in ISMS (ISO 27001) The completed sentence likely reads something like: > "Top management should [review] the ISMS through a [Management Review] process to [assess] at [regular] intervals the [suitability], adequacy, and effectiveness of the…

Information Security Management System Requirements

Question

Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of the Check stage of the Plan-Do-Check-Act cycle in respect of the operation of the information security management system. You do this by asking him to select the words that best complete the sentence:

To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:

Exhibit

LEAD-AUDITOR question #326 exhibit

Answer Area

Drag items

plannedassessRisk AssessmentefficiencysuitabilityreviewRisk ManagementregularManagement Reviewrandom

Correct arrangement

  • review
  • Management Review
  • assess
  • regular
  • suitability

Explanation

Explanation: Check Stage of PDCA in ISMS (ISO 27001)

The completed sentence likely reads something like:

"Top management should [review] the ISMS through a [Management Review] process to [assess] at [regular] intervals the [suitability], adequacy, and effectiveness of the information security management system."

This maps directly to ISO 27001 Clause 9.3 (Management Review).


Item-by-Item Breakdown

1. review - The action performed in the Check stage

The Check stage is fundamentally about reviewing - evaluating whether what was planned and done is actually working. The verb "review" anchors the sentence and describes the core activity. "Audit" or "assess" could feel similar, but "review" here describes the overarching activity before the specific mechanism is named.

2. Management Review - The formal mechanism

ISO 27001 Clause 9.3 mandates a specific formal process called the Management Review, where top management evaluates the ISMS. This is a named, structured process - not just any review. It must be documented and cover defined inputs (audit results, incidents, objectives performance, etc.) and produce defined outputs. Confusing this with Risk Assessment or Risk Management is a common mistake - those belong to the Do or Plan stages.

3. assess - What happens during the review

Once the Management Review mechanism is invoked, its purpose is to assess performance. "Assess" is more precise here than "review" (already used) or "audit" (a separate formal process under Clause 9.2). During the Management Review, management assesses whether the ISMS is achieving its goals.

4. regular - The frequency requirement

ISO 27001 requires Management Reviews to occur at planned intervals - but many training materials and exam questions use regular to convey that these are not one-off or random events. "Random" would imply no structure, which directly contradicts the systematic nature of the Check stage. Using "planned" vs "regular" is a nuance - both appear in available items, but "regular" fits the blank better grammatically and contextually here.

5. suitability - The key outcome being evaluated

ISO 27001 Clause 9.3 states the review ensures the ISMS's continuing suitability, adequacy, and effectiveness. "Suitability" is the first and most governance-oriented of the three - it asks whether the ISMS still fits the organization's context and objectives. "Efficiency" is a distractor; ISO 27001 does not use efficiency as a key outcome measure for ISMS reviews. Suitability is the standard term from the specification.


Common Mistakes

MistakeWhy It's Wrong
Choosing Risk Assessment for blank 2Risk Assessment is a Plan/Do activity, not the Check mechanism
Choosing planned instead of regularBoth are plausible, but "regular" fits the sentence structure better in this context
Choosing efficiency instead of suitabilityISO 27001 uses suitability, adequacy, effectiveness - not efficiency
Choosing audit conceptuallyInternal audit (Clause 9.2) and Management Review (Clause 9.3) are separate Check-stage activities - the sentence is specifically about Management Review

Core takeaway: The Check stage is operationalized through the Management Review process, which happens at regular intervals and uses review/assess activities to confirm the ISMS's suitability - all anchored in ISO 27001 Clause 9.3.

Topics

#PDCA cycle#management review#ISMS#ISO 27001

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice