LEAD-AUDITOR · Question #40
The data center at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit a number of internal audits have been carried out by a…
The correct answer is A. The audit programme shows management reviews taking place at irregular intervals during the C. The audit programme does not take into account the relative importance of information security E. Although the scope for each internal audit has been defined, there are no audit criteria defined for F. Audit reports to date have used key performance indicator information to focus solely on the H. The audit programme does not take into account the results of previous audits I. Top management commitment to the ISMS will not be audited before the certification visit. You've hit your limit · resets 4am (America/New_York)
Question
The data center at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit a number of internal audits have been carried out by a colleague working at another data centre within your Group. They secured their ISO/IEC 27001:2022 certificate earlier in the year. You have just qualified as an Internal ISMS auditor and your manager has asked you to review the audit process and audit findings as a final check before the external Certrfication Body arrives. Which six of the following would cause you concern in respect of conformity to ISO/IEC 27001:2022 requirements?
Options
- AThe audit programme shows management reviews taking place at irregular intervals during the
- BAudit reports are not held in hardcopy (i.e. on paper). They are only stored as ".POF documents on
- CThe audit programme does not take into account the relative importance of information security
- DThe audit programme mandates auditors must be independent of the areas they audit in order to
- EAlthough the scope for each internal audit has been defined, there are no audit criteria defined for
- FAudit reports to date have used key performance indicator information to focus solely on the
- GThe audit programme does not reference audit methods or audit responsibilities
- HThe audit programme does not take into account the results of previous audits
- ITop management commitment to the ISMS will not be audited before the certification visit,
- JThe audit process states the results of audits will be made available to 'relevant' managers, not top
How the community answered
(19 responses)- A68% (13)
- B16% (3)
- D11% (2)
- G5% (1)
Explanation
You've hit your limit · resets 4am (America/New_York)
Topics
Community Discussion
No community discussion yet for this question.