Exit ISO-IEC-27001-LEAD-AUDITOR PECB Certified ISO/IEC 27001 Lead Auditor exam
Question 4 of 5
0% complete
Q4 Multiple choice

You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and included all the information security controls in ISO/IEC 27001:2022 Appendix A in their Statement of Applicability.

During the Stage 2 audit, your audit team found that there was no evidence of a risk treatment plan for the implementation of the three controls (5.3 Segregation of duties, 6.1 Screening, 7.12 Cabling security). You raise a nonconformity against clause 6.1.3.e of ISO 27001:2022.

At the closing meeting, the Technical Director issues an extract from an amended Statement of Applicability (as shown) and asks for the nonconformity to be withdrawn.

Select three options of the correct responses of an audit team leader to the request of the Technical Director.

Select all that apply.

  • A

    Advise management that the information provided will be reviewed when the auditors have more time.

  • B

    Advise the Technical Director that his request will be included in the audit report.

  • C

    Advise the Technical Director that once a nonconformity is raised it cannot be withdrawn.

  • D

    Advise the Technical Director that the nonconformity must stand since the evidence obtained for it was clear.

  • E

    Ask the auditor who raised the issue for their opinion on how you should respond to the request.

  • F

    Inform the Technical Director that the nonconformity will be changed to an Opportunity for Improvement.

  • G

    Review the documentation produced and withdraw the nonconformity.

  • H

    State that a follow up audit will be necessary to review the evidence for the updated Statement of

    Applicability.