Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 1 Question 73 Discussion

Scenario 9: CoreBit SystemsCoreBit Systems, with its headquarters m San Francisco, specializes in information and communication technology (ICT) solutions, its clientele primarily includes data communication enterprises and network operators. The company's core objective is to enable its clients a smooth transition into multi-service providers, aligning their operations with the complex demands of the digital landscape.Recently. John, the internal auditor of CoreBit Systems, conducted an internal audit which uncovered nonconformities related to their monitoring procedures and system vulnerabilities, in response to the identified nonconformities. CoreBit Systems decided to employ a comprehensive problem-solving approach to solve these issues systematically. The method encompasses a team-oriented approach, aiming to identify, correct, and eliminate the root causes of issues. This approach involves several steps. First, establish a group of experts with deep knowledge of processes and controls. Next, break down the nonconformity into measurable components and implement interim containment measures. Then, identify potential root causes and select and verify permanent corrective actions. Finally, put those actions into practice, validate them, take steps to prevent recurrence, and recognize and acknowledge the team's efforts.Following the analysis of the root cause of the nonconformities, CoreBit Systems's ISMS project manager. Julia, developed a list of potential actions to address the identified nonconformities. Julia carefully evaluated the list to ensure that each action would effectively eliminate the root cause of the respective nonconformity. While assessing potential corrective action for addressing a nonconformity, Julia identified the issue as significant and assessed a high likelihood of its reoccurrence Consequently, she chose to implement temporary corrective actions. Afterward. Julia combined all the nonconformities Into a single action plan and sought approval from the top management.The submitted action plan was written as follows:A new version of the access control policy will be established and new restrictions will be created to ensure that network access is effectively managed and monitored by the Information and Communication Technology (ICT) Department.However. Julia's submitted action plan was not approved by top management The reason cited was that a general action plan meant to address all nonconformities was deemed unacceptable. Consequently, Julia revised the action plan and submitted separate ones for approval Unfortunately, Julia did not adhere to the organization's specified deadline for submission, resulting in a delay in the corrective action process, and notably, the revised action plans lacked a defined schedule for execution.Julia, the ISMS project manager, developed a combined action plan for all nonconformities. However, it was rejected, revised, and resubmitted late---without defined execution schedules.Did CoreBit Systems have a plan in place to implement permanent corrective action to address the identified nonconformities?
B) No -- CoreBit Systems did not have a clear plan to implement a permanent corrective action
A) Yes -- CoreBit Systems had a comprehensive plan in place to implement permanent corrective actions
C) No -- CoreBit Systems decided not to pursue this course of action

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 1 Question 73 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 73
Topic #: 1
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 9: CoreBit Systems

CoreBit Systems, with its headquarters m San Francisco, specializes in information and communication technology (ICT) solutions, its clientele primarily includes data communication enterprises and network operators. The company's core objective is to enable its clients a smooth transition into multi-service providers, aligning their operations with the complex demands of the digital landscape.

Recently. John, the internal auditor of CoreBit Systems, conducted an internal audit which uncovered nonconformities related to their monitoring procedures and system vulnerabilities, in response to the identified nonconformities. CoreBit Systems decided to employ a comprehensive problem-solving approach to solve these issues systematically. The method encompasses a team-oriented approach, aiming to identify, correct, and eliminate the root causes of issues. This approach involves several steps. First, establish a group of experts with deep knowledge of processes and controls. Next, break down the nonconformity into measurable components and implement interim containment measures. Then, identify potential root causes and select and verify permanent corrective actions. Finally, put those actions into practice, validate them, take steps to prevent recurrence, and recognize and acknowledge the team's efforts.

Following the analysis of the root cause of the nonconformities, CoreBit Systems's ISMS project manager. Julia, developed a list of potential actions to address the identified nonconformities. Julia carefully evaluated the list to ensure that each action would effectively eliminate the root cause of the respective nonconformity. While assessing potential corrective action for addressing a nonconformity, Julia identified the issue as significant and assessed a high likelihood of its reoccurrence Consequently, she chose to implement temporary corrective actions. Afterward. Julia combined all the nonconformities Into a single action plan and sought approval from the top management.

The submitted action plan was written as follows:

A new version of the access control policy will be established and new restrictions will be created to ensure that network access is effectively managed and monitored by the Information and Communication Technology (ICT) Department.

However. Julia's submitted action plan was not approved by top management The reason cited was that a general action plan meant to address all nonconformities was deemed unacceptable. Consequently, Julia revised the action plan and submitted separate ones for approval Unfortunately, Julia did not adhere to the organization's specified deadline for submission, resulting in a delay in the corrective action process, and notably, the revised action plans lacked a defined schedule for execution.

Julia, the ISMS project manager, developed a combined action plan for all nonconformities. However, it was rejected, revised, and resubmitted late---without defined execution schedules.

Did CoreBit Systems have a plan in place to implement permanent corrective action to address the identified nonconformities?

Show Suggested Answer Hide Answer
Suggested Answer: B

ISO/IEC 27001:2022 Clause 10.2 -- Nonconformity and corrective action requires:

''Corrective actions shall be implemented without undue delay and include:

--- evaluating the need for action to eliminate the cause;

--- implementing the necessary actions;

--- reviewing the effectiveness;

--- updating risks and SoA if needed.''

Although Julia drafted an action plan, it was not approved initially, was resubmitted late, and lacked scheduling---failing to meet key requirements of a ''clear and actionable plan.''


ISO/IEC 27001:2022 Clause 10.2===========

Contribute your Thoughts:

0/2000 characters
Rosenda
1 day ago
I think they could've done better with the execution timelines.
upvoted 0 times
...
Georgene
6 days ago
No clear plan? That's a huge oversight.
upvoted 0 times
...
Argelia
11 days ago
Surprised they didn't stick to the deadline! That's a big deal.
upvoted 0 times
...
Georgiann
17 days ago
Totally agree, they should've had separate plans from the start.
upvoted 0 times
...
Shannan
22 days ago
CoreBit had a plan but it got rejected.
upvoted 0 times
...
Benton
27 days ago
I recall that having a defined execution schedule is crucial for accountability. Julia's late submission really complicates things for CoreBit Systems.
upvoted 0 times
...
Devon
1 month ago
I'm a bit uncertain about whether they actually had a permanent corrective action in place. It feels like they were just reacting to the issues without a long-term strategy.
upvoted 0 times
...
Renay
1 month ago
I think I read a similar case where a combined action plan was also rejected. It makes sense that separate plans would be more effective, but I’m not sure if they had a solid timeline.
upvoted 0 times
...
Yaeko
1 month ago
I remember discussing how important it is to have a clear plan for corrective actions, but it seems like Julia's plan was too general and got rejected.
upvoted 0 times
...

Save Cancel