Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 109 páginas
Examen

NEWEST ISO 27001 INFORMATION SECURITY MANAGEMENT - LEAD AUDITOR CERTIFICATION EXAM OFFERED BY CQI & IRCA | COMPLETE EXAM Q&A WITH RATIONALES

Document preview thumbnail
Vista previa 4 fuera de 109 páginas

NEWEST ISO 27001 INFORMATION SECURITY MANAGEMENT - LEAD AUDITOR CERTIFICATION EXAM OFFERED BY CQI & IRCA | COMPLETE EXAM Q&A WITH RATIONALES

Vista previa del contenido

NEWEST ISO 27001 INFORMATION SECURITY
MANAGEMENT - LEAD AUDITOR
CERTIFICATION EXAM OFFERED BY CQI &
IRCA | COMPLETE EXAM Q&A WITH
RATIONALES


1. A software development company is undergoing its
initial ISO 27001:2022 certification audit. During the
Stage 1 documentation review, the lead auditor notes
that the company's information security policy is a
single-page document dated five years ago. The
policy makes no reference to cloud computing,
remote working, or mobile devices, all of which are
now core to the company's operations. The CEO
explains, “The policy is a high-level statement; we
don't want to change it every time the technology
changes.” Based on Clause 5.2 of ISO 27001:2022,
what is the auditor's most appropriate
determination?


A) The policy is acceptable because it is a high-level
document and does not need to reflect specific
technologies.
B) The policy is nonconforming because Clause 5.2
requires the policy to be appropriate to the purpose

,and context of the organization, which has materially
changed.
C) The policy is nonconforming because Clause 5.2
requires the policy to be reviewed and approved by
an external certification body.
D) The policy is acceptable as long as it is
communicated to all employees, regardless of its
content.
Correct answer: B
Rationale: Clause 5.2 of ISO 27001:2022 requires the
information security policy to be appropriate to the
purpose and context of the organization. The context,
including the use of cloud computing and remote
working, has changed, but the policy has not been
updated. This is a nonconformity against Clause 5.2.


2. An organization is preparing for its ISO 27001:2022
certification audit. The information security manager
has prepared the risk assessment methodology.
During the audit, the lead auditor asks to see the
criteria used to determine the likelihood and impact
of identified information security risks. The risk
manager explains, “We don’t formally document
criteria; our team has ten years of experience, so we
rely on their judgment.” According to Clause 6.1.2 of

,ISO 27001:2022, what is the auditor's most
appropriate response?


A) The reliance on expert judgment is acceptable if
the assessors are qualified.
B) The organization is nonconforming because
Clause 6.1.2 requires the organization to define and
apply a risk assessment process that includes
established criteria for likelihood and impact.
C) The organization is nonconforming because all
risk assessments must be performed by external
consultants.
D) The organization is conforming as long as the risk
assessment results are documented.
Correct answer: B
Rationale: Clause 6.1.2 requires the organization to
define and apply an information security risk
assessment process that includes establishing and
maintaining risk criteria, including acceptance
criteria and criteria for performing risk assessments.
Undocumented expert judgment does not meet this
requirement.


3. A financial institution is preparing its Statement of
Applicability (SoA) as part of its ISO 27001:2022

, implementation. The SoA lists 30 of the 93 Annex A
controls as “applicable.” For the remaining 63
controls, the justification simply states “not
applicable.” No explanation is provided for any of
them. Based on the requirements for the SoA under
Clause 6.1.3, what is the auditor's most appropriate
evaluation?


A) The SoA is acceptable; it is not required to justify
the exclusion of controls.
B) The SoA is nonconforming because Clause
6.1.3(d) requires the SoA to contain a justification for
whether each control is implemented or not, as well
as the justification for their inclusion or exclusion.
C) The SoA is acceptable as long as the controls
deemed not applicable are indeed not needed.
D) The SoA is nonconforming because the
organization must implement all 93 controls.
Correct answer: B
Rationale: Clause 6.1.3(d) of ISO 27001:2022
explicitly requires the Statement of Applicability
(SoA) to contain a justification for whether each
Annex A control is implemented or not, as well as the
justification for their inclusion or exclusion.

Información del documento

Subido en
9 de junio de 2026
Número de páginas
109
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$23.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
IsaacRobie
4.0
(78)
Vendido
341
Seguidores
156
Artículos
4368
Última venta
1 semana hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes