NEWEST ISO 27001 INFORMATION SECURITY
MANAGEMENT - LEAD AUDITOR
CERTIFICATION EXAM OFFERED BY CQI &
IRCA | COMPLETE EXAM Q&A WITH
RATIONALES
1. A software development company is undergoing its
initial ISO 27001:2022 certification audit. During the
Stage 1 documentation review, the lead auditor notes
that the company's information security policy is a
single-page document dated five years ago. The
policy makes no reference to cloud computing,
remote working, or mobile devices, all of which are
now core to the company's operations. The CEO
explains, “The policy is a high-level statement; we
don't want to change it every time the technology
changes.” Based on Clause 5.2 of ISO 27001:2022,
what is the auditor's most appropriate
determination?
A) The policy is acceptable because it is a high-level
document and does not need to reflect specific
technologies.
B) The policy is nonconforming because Clause 5.2
requires the policy to be appropriate to the purpose
,and context of the organization, which has materially
changed.
C) The policy is nonconforming because Clause 5.2
requires the policy to be reviewed and approved by
an external certification body.
D) The policy is acceptable as long as it is
communicated to all employees, regardless of its
content.
Correct answer: B
Rationale: Clause 5.2 of ISO 27001:2022 requires the
information security policy to be appropriate to the
purpose and context of the organization. The context,
including the use of cloud computing and remote
working, has changed, but the policy has not been
updated. This is a nonconformity against Clause 5.2.
2. An organization is preparing for its ISO 27001:2022
certification audit. The information security manager
has prepared the risk assessment methodology.
During the audit, the lead auditor asks to see the
criteria used to determine the likelihood and impact
of identified information security risks. The risk
manager explains, “We don’t formally document
criteria; our team has ten years of experience, so we
rely on their judgment.” According to Clause 6.1.2 of
,ISO 27001:2022, what is the auditor's most
appropriate response?
A) The reliance on expert judgment is acceptable if
the assessors are qualified.
B) The organization is nonconforming because
Clause 6.1.2 requires the organization to define and
apply a risk assessment process that includes
established criteria for likelihood and impact.
C) The organization is nonconforming because all
risk assessments must be performed by external
consultants.
D) The organization is conforming as long as the risk
assessment results are documented.
Correct answer: B
Rationale: Clause 6.1.2 requires the organization to
define and apply an information security risk
assessment process that includes establishing and
maintaining risk criteria, including acceptance
criteria and criteria for performing risk assessments.
Undocumented expert judgment does not meet this
requirement.
3. A financial institution is preparing its Statement of
Applicability (SoA) as part of its ISO 27001:2022
, implementation. The SoA lists 30 of the 93 Annex A
controls as “applicable.” For the remaining 63
controls, the justification simply states “not
applicable.” No explanation is provided for any of
them. Based on the requirements for the SoA under
Clause 6.1.3, what is the auditor's most appropriate
evaluation?
A) The SoA is acceptable; it is not required to justify
the exclusion of controls.
B) The SoA is nonconforming because Clause
6.1.3(d) requires the SoA to contain a justification for
whether each control is implemented or not, as well
as the justification for their inclusion or exclusion.
C) The SoA is acceptable as long as the controls
deemed not applicable are indeed not needed.
D) The SoA is nonconforming because the
organization must implement all 93 controls.
Correct answer: B
Rationale: Clause 6.1.3(d) of ISO 27001:2022
explicitly requires the Statement of Applicability
(SoA) to contain a justification for whether each
Annex A control is implemented or not, as well as the
justification for their inclusion or exclusion.
MANAGEMENT - LEAD AUDITOR
CERTIFICATION EXAM OFFERED BY CQI &
IRCA | COMPLETE EXAM Q&A WITH
RATIONALES
1. A software development company is undergoing its
initial ISO 27001:2022 certification audit. During the
Stage 1 documentation review, the lead auditor notes
that the company's information security policy is a
single-page document dated five years ago. The
policy makes no reference to cloud computing,
remote working, or mobile devices, all of which are
now core to the company's operations. The CEO
explains, “The policy is a high-level statement; we
don't want to change it every time the technology
changes.” Based on Clause 5.2 of ISO 27001:2022,
what is the auditor's most appropriate
determination?
A) The policy is acceptable because it is a high-level
document and does not need to reflect specific
technologies.
B) The policy is nonconforming because Clause 5.2
requires the policy to be appropriate to the purpose
,and context of the organization, which has materially
changed.
C) The policy is nonconforming because Clause 5.2
requires the policy to be reviewed and approved by
an external certification body.
D) The policy is acceptable as long as it is
communicated to all employees, regardless of its
content.
Correct answer: B
Rationale: Clause 5.2 of ISO 27001:2022 requires the
information security policy to be appropriate to the
purpose and context of the organization. The context,
including the use of cloud computing and remote
working, has changed, but the policy has not been
updated. This is a nonconformity against Clause 5.2.
2. An organization is preparing for its ISO 27001:2022
certification audit. The information security manager
has prepared the risk assessment methodology.
During the audit, the lead auditor asks to see the
criteria used to determine the likelihood and impact
of identified information security risks. The risk
manager explains, “We don’t formally document
criteria; our team has ten years of experience, so we
rely on their judgment.” According to Clause 6.1.2 of
,ISO 27001:2022, what is the auditor's most
appropriate response?
A) The reliance on expert judgment is acceptable if
the assessors are qualified.
B) The organization is nonconforming because
Clause 6.1.2 requires the organization to define and
apply a risk assessment process that includes
established criteria for likelihood and impact.
C) The organization is nonconforming because all
risk assessments must be performed by external
consultants.
D) The organization is conforming as long as the risk
assessment results are documented.
Correct answer: B
Rationale: Clause 6.1.2 requires the organization to
define and apply an information security risk
assessment process that includes establishing and
maintaining risk criteria, including acceptance
criteria and criteria for performing risk assessments.
Undocumented expert judgment does not meet this
requirement.
3. A financial institution is preparing its Statement of
Applicability (SoA) as part of its ISO 27001:2022
, implementation. The SoA lists 30 of the 93 Annex A
controls as “applicable.” For the remaining 63
controls, the justification simply states “not
applicable.” No explanation is provided for any of
them. Based on the requirements for the SoA under
Clause 6.1.3, what is the auditor's most appropriate
evaluation?
A) The SoA is acceptable; it is not required to justify
the exclusion of controls.
B) The SoA is nonconforming because Clause
6.1.3(d) requires the SoA to contain a justification for
whether each control is implemented or not, as well
as the justification for their inclusion or exclusion.
C) The SoA is acceptable as long as the controls
deemed not applicable are indeed not needed.
D) The SoA is nonconforming because the
organization must implement all 93 controls.
Correct answer: B
Rationale: Clause 6.1.3(d) of ISO 27001:2022
explicitly requires the Statement of Applicability
(SoA) to contain a justification for whether each
Annex A control is implemented or not, as well as the
justification for their inclusion or exclusion.