EXAMINATION WITH QUESTIONS AND
VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. An organization has established a security management system
(SMS) for its international supply-chain operations. During a Stage
1 audit, the audit team discovers that the organization has
identified theft, unauthorized access, cargo tampering, cyber
disruption, and terrorism as security risks, but there is no
documented methodology explaining how these risks were
evaluated or prioritized. What should the lead auditor conclude?
A. The organization automatically conforms because all major threats
have been identified
B. The organization should be considered conforming because
documented risk methodology is optional
C. The auditor should evaluate whether the organization's security-risk
assessment process is adequately defined, implemented, and effective
D. The organization must immediately terminate its supply-chain
operations
Answer: C. The auditor should evaluate whether the organization's
security-risk assessment process is adequately defined,
implemented, and effective
Rationale: Identification of threats alone does not demonstrate an
effective security management process. A lead auditor should assess
whether the organization has established an appropriate, systematic
method for determining and addressing security risks and whether that
1
,method is implemented consistently. The audit conclusion should be
based on objective evidence rather than simply on the existence of a
list of threats.
2. During an ISO 28000 audit, the security manager tells the auditor
that all security controls were designed by senior management five
years ago and have never been formally reviewed because "nothing
serious has happened." Several new logistics providers and
international routes have been introduced since then. What is the
most appropriate audit response?
A. Accept the explanation because the organization has experienced no
major incident
B. Determine whether changes in the organization's context, risks,
operations, and supply-chain environment require review and updating
of the SMS
C. Issue an automatic major nonconformity solely because the controls
are five years old
D. Ignore the controls and focus exclusively on physical security
Answer: B. Determine whether changes in the organization's
context, risks, operations, and supply-chain environment require
review and updating of the SMS
Rationale: Security management must remain appropriate to the
organization's circumstances. Changes to routes, suppliers,
technologies, facilities, threats, legal requirements, and operating
conditions can alter security risks. The auditor should therefore seek
objective evidence that the organization reviews and maintains the
SMS in response to relevant changes rather than relying solely on
historical performance.
2
, 3. An auditor is reviewing the organization's security objectives. The
organization has established the objective "improve supply-chain
security." No measurable indicators, responsibilities, timeframes,
resources, or evaluation criteria have been established. Which audit
concern is most appropriate?
A. The objective is sufficiently detailed because security improvement is
inherently qualitative
B. The objective should be evaluated for whether it is appropriately
established, monitored, and supported by planning and performance
criteria
C. Objectives are unnecessary under ISO 28000
D. Only financial objectives need to be measurable
Answer: B. The objective should be evaluated for whether it is
appropriately established, monitored, and supported by planning
and performance criteria
Rationale: Security objectives should provide meaningful direction for
the SMS and should be capable of being monitored and evaluated. An
objective such as "improve supply-chain security" may be too vague
unless translated into appropriate indicators, responsibilities, actions,
resources, and evaluation methods.
4. During an audit of a multinational logistics company, the auditor
discovers that one distribution center has its own security
procedures, separate risk assessments, and separate incident-
reporting process. Headquarters claims that the center is "outside
the SMS" even though it handles shipments included in the
organization's declared scope. What should the lead auditor do
first?
A. Accept headquarters' statement without further examination
B. Determine the documented scope and assess whether the distribution
3
, center is actually within it
C. Immediately certify the headquarters only
D. Delete the distribution center from the audit evidence
Answer: B. Determine the documented scope and assess whether the
distribution center is actually within it
Rationale: Audit conclusions depend on the defined scope of the
management system. The auditor should establish what activities,
locations, functions, and processes are included and then determine
whether the distribution center falls within that scope. If it does, its
relevant security-management arrangements must be considered
during the audit.
5. An organization outsources container transportation to a third-
party carrier. The carrier performs security checks, driver
verification, GPS monitoring, and incident reporting. The
organization argues that these activities are irrelevant to its ISO
28000 SMS because the carrier is an independent company. Which
statement is most appropriate?
A. Outsourced processes can automatically be excluded from the SMS
B. The organization remains responsible for controlling relevant
outsourced processes that can affect the intended outcomes of its SMS
C. The carrier must become ISO 28000 certified before any
transportation can occur
D. Outsourcing eliminates the organization's security responsibilities
Answer: B. The organization remains responsible for controlling
relevant outsourced processes that can affect the intended outcomes
of its SMS
Rationale: Outsourcing does not automatically remove organizational
responsibility. Where an outsourced process can affect supply-chain
4