Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 1 Question 67 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 67
Topic #: 1
[All ISO-IEC-27001-Lead-Auditor Questions]

During a certification audit, the auditee proved to the auditor through documented information that it had conducted a risk assessment and had selected a number of controls to ensure information security. What should the auditor verify in this case?

Show Suggested Answer Hide Answer
Suggested Answer: C

The auditor should verify that the selected controls are included in the Statement of Applicability (SoA), making option C the correct answer. ISO/IEC 27001:2022 requires organizations to document which Annex A controls are applicable based on the results of the risk assessment and risk treatment process. The SoA is the formal document that records these decisions, including justification for inclusion or exclusion of controls.

The existence of a risk assessment alone is not sufficient. Auditors must confirm traceability between identified risks, selected controls, and their formal documentation in the SoA. This ensures transparency, consistency, and accountability in how the organization manages information security risks.

Option A is incorrect because ISO/IEC 27001 does not require organizations to use external consultants for risk assessments. Risk assessments may be conducted internally, provided they follow a defined and systematic methodology. Option B is incorrect because controls can be preventive, detective, or corrective; there is no requirement that selected controls be corrective only.

Therefore, verifying that selected controls are properly reflected in the Statement of Applicability is a mandatory audit activity and a core requirement of ISO/IEC 27001 compliance.


Contribute your Thoughts:

0/2000 characters
Aaron
2 days ago
I remember a practice question about verifying controls, and I think it was important that they weren't all corrective.
upvoted 0 times
...
Ressie
7 days ago
I think the auditor needs to check if the selected controls are documented in the Statement of Applicability, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel