New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 5 Question 51 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 51
Topic #: 5
[All ISO-IEC-27001-Lead-Auditor Questions]

Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and commercial law, intellectual property, banking, and financial services. They believe they have a comfortable position in the market thanks to their commitment to implement information security best practices and remain up to date with technological developments.

Lawsy has implemented, evaluated, and conducted internal audits for an ISMS rigorously for two years now. Now, they have applied for ISO/IEC 27001 certification to ISMA, a well-known and trusted certification body.

During stage 1 audit, the audit team reviewed all the ISMS documents created during the implementation. They also reviewed and evaluated the records from management reviews and internal audits.

Lawsy submitted records of evidence that corrective actions on nonconformities were performed when necessary, so the audit team interviewed the internal auditor. The interview validated the adequacy and frequency of the internal audits by providing detailed insight into the internal audit plan and procedures.

The audit team continued with the verification of strategic documents, including the information security policy and risk evaluation criteri

a. During the information security policy review, the team noticed inconsistencies between the documented information describing governance framework (i.e., the information security policy) and the procedures.

Although the employees were allowed to take the laptops outside the workplace, Lawsy did not have procedures in place regarding the use of laptops in such cases. The policy only provided general information about the use of laptops. The company relied on employees' common knowledge to protect the confidentiality and integrity of information stored in the laptops. This issue was documented in the stage 1 audit report.

Upon completing stage 1 audit, the audit team leader prepared the audit plan, which addressed the audit objectives, scope, criteria, and procedures.

During stage 2 audit, the audit team interviewed the information security manager, who drafted the information security policy. He justified the Issue identified in stage 1 by stating that Lawsy conducts mandatory information security training and awareness sessions every three months.

Following the interview, the audit team examined 15 employee training records (out of 50) and concluded that Lawsy meets requirements of ISO/IEC 27001 related to training and awareness. To support this conclusion, they photocopied the examined employee training records.

Based on the scenario above, answer the following question:

The audit team photocopied the examined employee training records to support their conclusion. Should the audit team obtain an approval from Lawsy before taking this action? Refer to scenario 7.

Show Suggested Answer Hide Answer
Suggested Answer: B

Yes, the audit team should obtain approval from Lawsy before photocopying documents. This is a best practice to ensure that the auditee agrees to the duplication of documents, which might contain sensitive or confidential information. Although auditors can observe and note down information, copying documents typically requires explicit permission to maintain trust and ensure compliance with confidentiality agreements.


Contribute your Thoughts:

0/2000 characters
Yesenia
3 months ago
I wonder if Lawsy's policy covers this kind of situation at all.
upvoted 0 times
...
Darci
3 months ago
No doubt, they have the authority to do that for verification purposes.
upvoted 0 times
...
Cherri
3 months ago
Wait, can they really photocopy without permission? Seems a bit off.
upvoted 0 times
...
Lucina
4 months ago
Totally agree, it's just good practice to ask first!
upvoted 0 times
...
Maile
4 months ago
I think the audit team should definitely get approval before photocopying anything.
upvoted 0 times
...
Chantell
4 months ago
I recall a similar question where the emphasis was on the audit team's responsibilities. If they need to verify something, they might not need prior approval, but it feels a bit tricky.
upvoted 0 times
...
Dorothea
4 months ago
From what I practiced, I believe the audit team has the authority to photocopy documents for verification purposes. It’s part of their role to ensure compliance.
upvoted 0 times
...
Sanjuana
4 months ago
I'm not entirely sure, but I remember something about needing consent from the auditee for taking notes or copies. It might depend on the audit agreement.
upvoted 0 times
...
Lynelle
5 months ago
I think the audit team should definitely get approval before photocopying any documents. It seems like a matter of respecting the auditee's rights.
upvoted 0 times
...
Ming
5 months ago
I'm a little unsure about this one. On one hand, the audit team was just trying to verify the training records, which seems reasonable. But I can also see how the company might want to know if their internal documents are being copied. Maybe there's a middle ground where the team informs the company they'll be photocopying some records, but doesn't need explicit approval each time.
upvoted 0 times
...
Tamie
5 months ago
The audit team doesn't need approval to photocopy the documents. As part of the audit, they have the authority to review and verify the evidence, which includes making copies if necessary. As long as they're not taking anything confidential or sensitive, they should be able to photocopy what they need to support their findings.
upvoted 0 times
...
Edda
5 months ago
I think the audit team should get approval before photocopying the documents. Even though they were just verifying the training, it's the company's private information and they should respect the auditee's privacy. Better to be safe and get permission first.
upvoted 0 times
...
Onita
5 months ago
Hmm, this is a tricky one. I'm not sure if the audit team needs to get approval before photocopying the training records. The scenario says they were verifying the existence of the training, so it seems like they were just documenting their findings. But I could see how the company might want to know if their records were being copied.
upvoted 0 times
...
Della
1 year ago
Personally, I'd be a bit wary of letting auditors photocopy sensitive documents. What if they accidentally leave them in the copy machine and the cleaning crew finds them? Better safe than sorry, I say.
upvoted 0 times
...
Lucy
1 year ago
Ah, the age-old debate of auditor rights versus auditee privacy. I say, as long as the auditors don't make copies of the company's secret recipe for world domination, it's all good!
upvoted 0 times
...
Quentin
1 year ago
I think the audit team has the authority to photocopy documents as needed to verify conformity. They're just doing their job properly.
upvoted 0 times
Marisha
1 year ago
I agree, it's important to get approval before photocopying documents during an audit.
upvoted 0 times
...
Nobuko
1 year ago
A) Yes. the audit team should obtain the approval of the auditee when verifying the existence of a process in all cases, including when taking notes and photocopying documents
upvoted 0 times
...
...
Shaun
1 year ago
The audit team definitely needs approval before photocopying any documents. It's a matter of respecting the auditee's privacy and confidentiality.
upvoted 0 times
Ira
1 year ago
A) Yes. the audit team should obtain the approval of the auditee when verifying the existence of a process in all cases, including when taking notes and photocopying documents
upvoted 0 times
...
Shawna
1 year ago
B) Yes, the audit team can photocopy documents observed during the audit if the auditee agrees to it
upvoted 0 times
...
Mose
1 year ago
A) Yes. the audit team should obtain the approval of the auditee when verifying the existence of a process in all cases, including when taking notes and photocopying documents
upvoted 0 times
...
...
Lino
1 year ago
I disagree. The audit team has the authority to photocopy documents to verify conformity.
upvoted 0 times
...
Lajuana
1 year ago
I agree with Laura. It's important to respect the auditee's privacy and get their consent.
upvoted 0 times
...
Laura
1 year ago
I think the audit team should obtain approval before photocopying documents.
upvoted 0 times
...

Save Cancel