Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam ISO-IEC-27001-Lead-Implementer Topic 6 Question 53 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 53
Topic #: 6
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 10:

NetworkFuse is a leading company that specializes in the design, production, and distribution of network hardware products. Over the past two years, NetworkFuse has maintained an operational Information Security Management System (ISMS) based on ISO/IEC 27001 requirements and a Quality Management System (QMS) based on ISO 9001. These systems are designed to ensure the company's commitment to both information security and the highest quality standards.

To further demonstrate its dedication to best practices and industry standards, NetworkFuse recently scheduled a combined certification audit. This audit seeks to validate NetworkFuse's compliance with both ISO/IEC 27001 and ISO 9001, showcasing the company's strong commitment to maintaining high standards in information security management and quality management. The process began with the careful selection of a certification body. NetworkFuse then took steps to prepare its employees for the audit, which was crucial for ensuring a smooth and successful audit process. Additionally, NetworkFuse appointed individuals to manage the ISMS and the QMS.

NetworkFuse decided not to conduct a self-evaluation before the audit, a step often taken by organizations to proactively identify potential areas for improvement. The company's top management believed such an evaluation was unnecessary, confident in their existing systems and practices. This decision reflected their trust in the robustness of their ISMS and QMS. As part of the preparations, NetworkFuse took careful measures to ensure that all necessary documented information---including internal audit reports, management reviews, technological infrastructure, and the overall functioning of the ISMS and QMS---was readily available for the audit. This information would be vital in demonstrating their compliance with the ISO standards.

During the audit, NetworkFuse requested that the certification body not carry documentation off-site. This request stemmed from their commitment to safeguarding sensitive and proprietary information, reflecting their desire for maximum security and control during the audit process. Despite meticulous preparations, the actual audit did not proceed as scheduled. NetworkFuse raised concerns about the assigned audit team leader and requested a replacement. The company asserted that the same audit team leader had previously issued a recommendation for certification to one of NetworkFuse's main competitors. This potential conflict of interest raised concerns among the company's top management. However, the certification body rejected NetworkFuse's request for a replacement, and the audit process was canceled.

Which of the following actions is NOT a requirement for NetworkFuse in preparing for the certification audit?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Cherri
1 days ago
I disagree, preparing the personnel is not a requirement for NetworkFuse in preparing for the certification audit.
upvoted 0 times
...
Kristine
4 days ago
Gathering documented information is obviously necessary, so that can't be the answer. I'm leaning towards option A, identifying subject matter experts.
upvoted 0 times
...
Stephanie
5 days ago
I think identifying subject matter experts is not a requirement for NetworkFuse in preparing for the certification audit.
upvoted 0 times
...
Anabel
8 days ago
Hmm, I'm not sure about the answer. Preparing the personnel seems like a crucial step, but I can't decide which one is not required.
upvoted 0 times
...

Save Cancel