Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 3 Question 64 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 64
Topic #: 3
[All ISO-IEC-27001-Lead-Auditor Questions]

Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, including deployment and maintenance. The company serves sectors like public services, finance, telecom, energy, healthcare, and education. As a customer-centered company, it prioritizes strong client relationships and leading security practices.

Techmanic has been ISO/IEC 27001 certified for a year and regards this certification with pride. During the certification audit, the auditor found some inconsistencies in its ISMS implementation. Since the observed situations did not affect the capability of its ISMS to achieve the intended results, Techmanic was certified after auditors followed up on the root cause analysis and corrective actions remotely During that year, the company added hosting to its list of services and requested to expand its certification scope to include that area The auditor in charge approved the request and notified Techmanic that the extension audit would be conducted during the surveillance audit

Techmanic underwent a surveillance audit to verify its iSMS's continued effectiveness and compliance with ISO/IEC 27001. The surveillance audit aimed to ensure that Techmanic's security practices, including the recent addition of hosting services, aligned seamlessly with the rigorous requirements of the certification

The auditor strategically utilized the findings from previous surveillance audit reports in the recertification activity with the purpose of replacing the need for additional recertification audits, specifically in the IT consultancy sector. Recognizing the value of continual improvement and learning from past assessments. Techmanic implemented a practice of reviewing previous surveillance audit reports. This proactive approach not only facilitated identifying and resolving potential nonconformities but also aimed to streamline the recertification process in the IT consultancy sector.

During the surveillance audit, several nonconformities were found. The ISMS continued to fulfill the ISO/IEC 27001*s requirements, but Techmanic failed to resolve the nonconformities related to the hosting services, as reported by its internal auditor. In addition, the internal audit report had several inconsistencies, which questioned the independence of the internal auditor during the audit of hosting services. Based on this, the extension certification was not granted. As a result. Techmanic requested a transfer to another certification body. In the meantime, the company released a statement to its clients stating that the ISO/IEC 27001 certification covers the IT services, as well as the hosting services.

Based on the scenario above, answer the following question:

Is the internal auditor responsible for following up on action plans resulting from external audits?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed In-Depth

A . Correct Answer:

Internal auditors focus on internal audit nonconformities, while external auditors oversee external audit follow-ups.

B . Incorrect:

Minor nonconformities do not change the role of internal auditors.

C . Incorrect:

Internal auditors do not follow up on external audit findings---this is the certification body's responsibility.

Relevant Standard Reference:

ISO/IEC 27001:2022 Clause 9.2.2 (Internal Audit Responsibilities)


Contribute your Thoughts:

0/2000 characters
Markus
15 days ago
It's all about accountability; the internal auditor should be on top of this!
upvoted 0 times
...
Roxane
20 days ago
Sounds like a mess, but they need to get their act together for hosting services.
upvoted 0 times
...
Vannessa
25 days ago
Wait, so the internal auditor had inconsistencies? That's surprising!
upvoted 0 times
...
Tammara
1 month ago
I disagree, that's usually the management's job, not the auditor's.
upvoted 0 times
...
Lajuana
1 month ago
Yes, the internal auditor should definitely follow up on action plans from external audits.
upvoted 0 times
...
Rebecka
1 month ago
The internal auditor is like a watchdog, but they can't do the actual training or process improvements. That's the company's job. Techmanic should have taken this more seriously.
upvoted 0 times
...
Apolonia
2 months ago
The internal auditor is like a detective - they find the problems, but the company has to do the real work to fix them. Sounds like Techmanic needs to get their act together!
upvoted 0 times
...
Diego
2 months ago
The internal auditor should be independent and objective, so they may not be the best party to follow up on external audit findings. That's the job of the management team.
upvoted 0 times
...
Portia
2 months ago
While the internal auditor may assist with follow-up, the ultimate responsibility lies with the organization's management to ensure corrective actions are taken.
upvoted 0 times
...
Lacey
2 months ago
The internal auditor should be responsible for following up on action plans resulting from external audits to ensure proper implementation and resolution of any issues.
upvoted 0 times
...
Izetta
2 months ago
From what I recall, internal auditors are usually expected to monitor action plans, but I’m not clear on whether that includes all external audit findings or just certain ones.
upvoted 0 times
...
Buddy
2 months ago
I feel like the internal auditor should definitely have some responsibility, but I wonder if there are specific guidelines that dictate how much they should be involved after an external audit.
upvoted 0 times
...
Lynelle
3 months ago
I practiced a similar question where the internal auditor had to ensure compliance after external audits. It seems like they should be involved in the follow-up process, right?
upvoted 0 times
...
Elli
3 months ago
I remember discussing the role of internal auditors in following up on action plans. I think they are responsible, but I'm not entirely sure how that ties into external audits specifically.
upvoted 0 times
...
Marge
4 months ago
The scenario suggests that the internal auditor is responsible for following up on action plans resulting from external audits. It mentions that Techmanic implemented a practice of reviewing previous surveillance audit reports, which indicates the internal auditor's involvement in addressing the nonconformities identified by the external auditor. The fact that the internal audit report had inconsistencies also implies the internal auditor's role in the follow-up process.
upvoted 0 times
...
Heike
4 months ago
I'm not entirely sure about the internal auditor's responsibility for following up on action plans from external audits. The scenario focuses more on the issues with the internal audit report and the extension certification, but doesn't directly state the internal auditor's role in the follow-up process. I'd need to do some additional research or analysis to feel confident in my answer.
upvoted 0 times
...
Hester
4 months ago
Based on the information provided, I believe the internal auditor is responsible for following up on action plans resulting from external audits. The scenario mentions that Techmanic implemented a practice of reviewing previous surveillance audit reports, which implies the internal auditor is involved in addressing the nonconformities identified by the external auditor. The internal auditor's role seems to be crucial in ensuring the company's continued compliance with the ISO/IEC 27001 standard.
upvoted 0 times
...
Florinda
4 months ago
I'm a bit confused on this one. The scenario doesn't explicitly state that the internal auditor is responsible for following up on action plans from external audits. It just says the internal audit report had inconsistencies, which led to the extension certification not being granted. I'm not sure if that means the internal auditor is responsible for the follow-up.
upvoted 0 times
...
Roslyn
4 months ago
I think the internal auditor is responsible for following up on action plans resulting from external audits. The scenario mentions that Techmanic implemented a practice of reviewing previous surveillance audit reports, which suggests the internal auditor plays a role in addressing nonconformities identified by the external auditor.
upvoted 0 times
...

Save Cancel