LEAD-AUDITOR · Question #326
Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the…
The correct answer is review; Management Review; assess; regular; suitability. Explanation: Check Stage of PDCA in ISMS (ISO 27001) The completed sentence likely reads something like: > "Top management should [review] the ISMS through a [Management Review] process to [assess] at [regular] intervals the [suitability], adequacy, and effectiveness of the…
Question
Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of the Check stage of the Plan-Do-Check-Act cycle in respect of the operation of the information security management system. You do this by asking him to select the words that best complete the sentence:
To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- review
- Management Review
- assess
- regular
- suitability
Explanation
Explanation: Check Stage of PDCA in ISMS (ISO 27001)
The completed sentence likely reads something like:
"Top management should [review] the ISMS through a [Management Review] process to [assess] at [regular] intervals the [suitability], adequacy, and effectiveness of the information security management system."
This maps directly to ISO 27001 Clause 9.3 (Management Review).
Item-by-Item Breakdown
1. review - The action performed in the Check stage
The Check stage is fundamentally about reviewing - evaluating whether what was planned and done is actually working. The verb "review" anchors the sentence and describes the core activity. "Audit" or "assess" could feel similar, but "review" here describes the overarching activity before the specific mechanism is named.
2. Management Review - The formal mechanism
ISO 27001 Clause 9.3 mandates a specific formal process called the Management Review, where top management evaluates the ISMS. This is a named, structured process - not just any review. It must be documented and cover defined inputs (audit results, incidents, objectives performance, etc.) and produce defined outputs. Confusing this with Risk Assessment or Risk Management is a common mistake - those belong to the Do or Plan stages.
3. assess - What happens during the review
Once the Management Review mechanism is invoked, its purpose is to assess performance. "Assess" is more precise here than "review" (already used) or "audit" (a separate formal process under Clause 9.2). During the Management Review, management assesses whether the ISMS is achieving its goals.
4. regular - The frequency requirement
ISO 27001 requires Management Reviews to occur at planned intervals - but many training materials and exam questions use regular to convey that these are not one-off or random events. "Random" would imply no structure, which directly contradicts the systematic nature of the Check stage. Using "planned" vs "regular" is a nuance - both appear in available items, but "regular" fits the blank better grammatically and contextually here.
5. suitability - The key outcome being evaluated
ISO 27001 Clause 9.3 states the review ensures the ISMS's continuing suitability, adequacy, and effectiveness. "Suitability" is the first and most governance-oriented of the three - it asks whether the ISMS still fits the organization's context and objectives. "Efficiency" is a distractor; ISO 27001 does not use efficiency as a key outcome measure for ISMS reviews. Suitability is the standard term from the specification.
Common Mistakes
| Mistake | Why It's Wrong |
|---|---|
Choosing Risk Assessment for blank 2 | Risk Assessment is a Plan/Do activity, not the Check mechanism |
Choosing planned instead of regular | Both are plausible, but "regular" fits the sentence structure better in this context |
Choosing efficiency instead of suitability | ISO 27001 uses suitability, adequacy, effectiveness - not efficiency |
Choosing audit conceptually | Internal audit (Clause 9.2) and Management Review (Clause 9.3) are separate Check-stage activities - the sentence is specifically about Management Review |
Core takeaway: The Check stage is operationalized through the Management Review process, which happens at regular intervals and uses review/assess activities to confirm the ISMS's suitability - all anchored in ISO 27001 Clause 9.3.
Topics
Community Discussion
No community discussion yet for this question.
