New Year Sale ! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam ISO-IEC-27001-Lead-Auditor Topic 5 Question 31 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 31
Topic #: 5
[All ISO-IEC-27001-Lead-Auditor Questions]

You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before being despatched to clients. You note that recently there has been a significant increase in the number of switches failing their initial configuration test and being returned for reprogramming.

You ask the Chief Tester why and she says, 'It's a result of the recent ISMS upgrade'. Before the upgrade each technician had their own hard copy work instructions. Now, the eight members of my team have to share two laptops to access the clients' configuration instructions online. These delays put pressure on the technicians, resulting in more mistakes being made'.

Based solely on the information above, which clause of ISO to raise a nonconformity against' Select one.

Show Suggested Answer Hide Answer
Suggested Answer: B

According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 8.1 requires an organization to plan, implement and control its processes needed to meet ISMS requirements2.This includes determining what needs to be done, how it will be done, who will do it, when it will be done, what resources are required, how performance will be evaluated, etc2. Therefore, if an ISMS auditor conducting a third-party surveillance audit of a telecom's provider notes that there has been a significant increase in the number of switches failing their initial configuration test and being returned for reprogramming due to a recent ISMS upgrade that reduced access to work instructions, this indicates a nonconformity against clause 8.1 of ISO/IEC 27001:2022.The organization has failed to plan and control its operational processes effectively to ensure information security and quality2. The other options are not correct clauses to raise a nonconformity against based solely on this information.For example, clause 7.5 deals with documented information required by ISMS or determined by an organization as necessary for its effectiveness2, but it does not specify how many copies or formats of work instructions should be available; clause 10.2 deals with nonconformity and corrective action as a response to an identified problem or incident2, but it does not address how to prevent or avoid such problems or incidents in operational processes; clause 7.3 deals with awareness of ISMS policy, objectives, roles and responsibilities among persons doing work under an organization's control2, but it does not relate to how work instructions are accessed or followed; clause 7.2 deals with competence of persons doing work under an organization's control that affects its ISMS performance2, but it does not imply that lack of competence is caused by insufficient work instructions; clause 7.4 deals with communication about ISMS among internal and external interested parties2, but it does not cover how operational information is communicated within an organization.Reference:ISO/IEC 27001:2022 - Information technology -- Security techniques -- Information security management systems -- Requirements


Contribute your Thoughts:

Gayla
6 months ago
I think Clause 7.4 - Communication could also be a factor here. If the team members are not able to communicate effectively and share resources, it can lead to delays and mistakes.
upvoted 0 times
...
Graciela
6 months ago
That's a valid point, Coletta. Competence is definitely essential in preventing errors during configuration.
upvoted 0 times
...
Coletta
6 months ago
I disagree, I believe the nonconformity should be raised against Clause 7.2 - Competence. If technicians are not properly equipped or trained, mistakes are bound to happen.
upvoted 0 times
...
Junita
6 months ago
I agree with you, Graciela. The issue seems to stem from the lack of proper operational planning and control.
upvoted 0 times
...
Graciela
6 months ago
I think the right clause to raise a nonconformity against is Clause 8.1 - Operational planning and control.
upvoted 0 times
...
Herminia
6 months ago
That's a good point, Emma. Maybe we need to consider Clause 7.2 as well
upvoted 0 times
...
Hershel
6 months ago
But could it also be related to Clause 7.2 - Competence? If technicians don't have the right resources, it could impact their competence
upvoted 0 times
...
Lillian
7 months ago
I agree with Sara, the issue seems to stem from operational planning and control
upvoted 0 times
...
Herminia
7 months ago
I think we should raise a nonconformity against Clause 8.1 - Operational planning and control
upvoted 0 times
...

Save Cancel