Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam ISO-IEC-27001-Lead-Auditor Topic 1 Question 34 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 34
Topic #: 1
[All ISO-IEC-27001-Lead-Auditor Questions]

The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?

Show Suggested Answer Hide Answer
Suggested Answer: A, B, E, F

According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 4.1 requires an organization to determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS2.External issues are those that originate from outside the organization, such as legal, regulatory, cultural, social, political, economic, natural and competitive factors2.Internal issues are those that originate from within the organization, such as governance, structure, roles and responsibilities, policies, objectives, culture, capabilities, resources and information systems2.Therefore, based on this definition, four examples of external issues in the context of a management system to ISO/IEC 27001:2022 are a rise in interest rates in response to high inflation (which affects the economic environment of the organization), a reduction in grants as a result of a change in government policy (which affects the political and legal environment of the organization), higher labour costs as a result of an aging population (which affects the social and demographic environment of the organization), and inability to source raw materials due to government sanctions (which affects the trade and supply environment of the organization)2. The other options are examples of internal issues, as they originate from within the organization or its activities.For example, poor levels of staff competence as a result of cuts in training expenditure (which affects the capabilities and resources of the organization), increased absenteeism as a result of poor management (which affects the culture and performance of the organization), poor morale as a result of staff holidays being reduced (which affects the motivation and satisfaction of the organization's personnel), and a fall in productivity linked to outdated production equipment (which affects the efficiency and quality of the organization's processes)2.Reference:ISO/IEC 27001:2022 - Information technology -- Security techniques -- Information security management systems -- Requirements


Contribute your Thoughts:

Dorinda
1 days ago
I believe it's detection risk, as the auditor failed to detect the issue.
upvoted 0 times
...
Tamesha
2 days ago
I agree with Chana, because it's related to the nature of the business.
upvoted 0 times
...
Lezlie
7 days ago
If the auditor can't even identify the network issues, I'm guessing they need a little more 'detection' in their diet.
upvoted 0 times
...
Chana
16 days ago
I think it's inherent risk.
upvoted 0 times
...

Save Cancel