New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 6 Question 53 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 53
Topic #: 6
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 10:

NetworkFuse is a leading company that specializes in the design, production, and distribution of network hardware products. Over the past two years, NetworkFuse has maintained an operational Information Security Management System (ISMS) based on ISO/IEC 27001 requirements and a Quality Management System (QMS) based on ISO 9001. These systems are designed to ensure the company's commitment to both information security and the highest quality standards.

To further demonstrate its dedication to best practices and industry standards, NetworkFuse recently scheduled a combined certification audit. This audit seeks to validate NetworkFuse's compliance with both ISO/IEC 27001 and ISO 9001, showcasing the company's strong commitment to maintaining high standards in information security management and quality management. The process began with the careful selection of a certification body. NetworkFuse then took steps to prepare its employees for the audit, which was crucial for ensuring a smooth and successful audit process. Additionally, NetworkFuse appointed individuals to manage the ISMS and the QMS.

NetworkFuse decided not to conduct a self-evaluation before the audit, a step often taken by organizations to proactively identify potential areas for improvement. The company's top management believed such an evaluation was unnecessary, confident in their existing systems and practices. This decision reflected their trust in the robustness of their ISMS and QMS. As part of the preparations, NetworkFuse took careful measures to ensure that all necessary documented information---including internal audit reports, management reviews, technological infrastructure, and the overall functioning of the ISMS and QMS---was readily available for the audit. This information would be vital in demonstrating their compliance with the ISO standards.

During the audit, NetworkFuse requested that the certification body not carry documentation off-site. This request stemmed from their commitment to safeguarding sensitive and proprietary information, reflecting their desire for maximum security and control during the audit process. Despite meticulous preparations, the actual audit did not proceed as scheduled. NetworkFuse raised concerns about the assigned audit team leader and requested a replacement. The company asserted that the same audit team leader had previously issued a recommendation for certification to one of NetworkFuse's main competitors. This potential conflict of interest raised concerns among the company's top management. However, the certification body rejected NetworkFuse's request for a replacement, and the audit process was canceled.

Which of the following actions is NOT a requirement for NetworkFuse in preparing for the certification audit?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Solange
3 months ago
Not sure skipping self-evaluation was a smart move...
upvoted 0 times
...
Stefanie
3 months ago
Gathering documented info is a must, right?
upvoted 0 times
...
Tawanna
3 months ago
Wait, they didn't want to change the audit leader? That's risky.
upvoted 0 times
...
Frederic
4 months ago
Totally agree, preparation is key!
upvoted 0 times
...
Lenny
4 months ago
They should've done a self-evaluation first!
upvoted 0 times
...
Eden
4 months ago
I recall that preparing personnel and gathering documentation are both critical steps, but I can't quite remember if identifying experts is mandatory or just a best practice.
upvoted 0 times
...
Dick
4 months ago
I feel a bit confused about the need for subject matter experts. I thought it was important, but maybe it’s not strictly required for the audit preparation?
upvoted 0 times
...
Murray
4 months ago
I practiced a similar question where gathering documented information was emphasized, so I feel like that's definitely a requirement for the audit.
upvoted 0 times
...
Stephaine
5 months ago
I remember studying the requirements for ISO audits, and I think preparing personnel is definitely essential, but I'm not sure about identifying subject matter experts.
upvoted 0 times
...
Loise
5 months ago
I agree with James on this one. The scenario specifically mentions that NetworkFuse chose not to do a self-evaluation, so that seems like the most likely answer that is not a requirement for them in this case.
upvoted 0 times
...
Maryln
5 months ago
Based on the details in the scenario, I think the answer is that conducting a self-evaluation before the audit is not a requirement. The text states that NetworkFuse decided not to do this, and it doesn't seem to be listed as a necessary step in their preparation process.
upvoted 0 times
...
Eleonore
5 months ago
I'm a bit confused by the request for NetworkFuse to not allow the certification body to take documentation off-site. That seems like an unusual requirement, so I'm wondering if that could be the answer. But I want to double-check the other options to be sure.
upvoted 0 times
...
Lashon
5 months ago
Okay, let me take a closer look at the information provided. It seems like NetworkFuse has already taken several important steps, like appointing ISMS and QMS managers and ensuring all necessary documentation is readily available. I think the key is to identify the actions that are not explicitly mentioned as requirements.
upvoted 0 times
...
Lavelle
5 months ago
This seems like a straightforward question, but I want to make sure I understand the key details before answering. The scenario describes NetworkFuse's preparation for a combined certification audit, and the question is asking about what is not a requirement for them in this process.
upvoted 0 times
...
Gennie
1 year ago
Haha, I bet the audit team leader had a 'conflicting interest' in the form of a hefty bribe from the competitor. Good call by NetworkFuse, even if it didn't work out.
upvoted 0 times
Jillian
1 year ago
Definitely, it's important to maintain integrity during audits.
upvoted 0 times
...
Arthur
1 year ago
Yeah, that sounds fishy. Good thing NetworkFuse raised concerns.
upvoted 0 times
...
...
Gracia
1 year ago
This is a tricky one. I think NetworkFuse should have done a self-evaluation before the audit. Skipping that step seems like the odd one out here.
upvoted 0 times
Mitzie
1 year ago
It's important to cover all bases when preparing for a certification audit.
upvoted 0 times
...
Celestina
1 year ago
I agree, a self-evaluation could have helped identify potential areas for improvement.
upvoted 0 times
...
...
Stephanie
1 year ago
Actually, gathering documented information is not a requirement for NetworkFuse in preparing for the certification audit.
upvoted 0 times
...
Cherri
1 year ago
I disagree, preparing the personnel is not a requirement for NetworkFuse in preparing for the certification audit.
upvoted 0 times
...
Kristine
1 year ago
Gathering documented information is obviously necessary, so that can't be the answer. I'm leaning towards option A, identifying subject matter experts.
upvoted 0 times
...
Stephanie
1 year ago
I think identifying subject matter experts is not a requirement for NetworkFuse in preparing for the certification audit.
upvoted 0 times
...
Anabel
1 year ago
Hmm, I'm not sure about the answer. Preparing the personnel seems like a crucial step, but I can't decide which one is not required.
upvoted 0 times
Carmelina
1 year ago
I think the answer is A) Identifying subject matter experts
upvoted 0 times
...
Lizbeth
1 year ago
C) Gathering documented information
upvoted 0 times
...
Dwight
1 year ago
B) Preparing the personnel
upvoted 0 times
...
Rosita
1 year ago
A) Identifying subject matter experts
upvoted 0 times
...
...

Save Cancel