Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 1 Question 68 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 68
Topic #: 1
[All ISO-IEC-27001-Lead-Auditor Questions]

According to ISO/IEC 27001, Clause 5.1 (Leadership and Commitment), which of the following is NOT a responsibility of top management?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed In-Depth

ISO/IEC 27001 Clause 5.1 (Leadership and Commitment) defines top management's role in ensuring the effectiveness of the Information Security Management System (ISMS). It requires top management to:

Ensure the availability of resources for the ISMS (Correct Responsibility).

Promote continual improvement of the ISMS (Correct Responsibility).

Direct and support employees to contribute to ISMS effectiveness (Correct Responsibility).

B . Conducting regular internal audits -- Incorrect Responsibility:

Internal audits are not a direct responsibility of top management. Instead, Clause 9.2 (Internal Audit) requires audits to be conducted independently of management.

Top management is responsible for ensuring audits are conducted but does not need to conduct them personally.

Thus, top management is responsible for oversight and support but not for conducting internal audits themselves.

Relevant Standard Reference:

ISO/IEC 27001:2022 Clause 5.1 (Leadership and Commitment)

ISO/IEC 27001:2022 Clause 9.2 (Internal Audit)


Contribute your Thoughts:

0/2000 characters
Olga
17 days ago
I practiced a similar question where it was clear that directing and supporting staff is a leadership role, so I think C is definitely a responsibility.
upvoted 0 times
...
Annelle
22 days ago
I’m not entirely sure, but I feel like conducting internal audits is more of an operational task rather than a top management responsibility.
upvoted 0 times
...
Nettie
27 days ago
I think I remember that top management is responsible for resource allocation and promoting improvement, so A seems correct.
upvoted 0 times
...

Save Cancel