Scenario 3
NightCore, a multinational technology enterprise headquartered in the United States, specializes in e-commerce, cloud computing, digital streaming, and artificial intelligence (AI). After having an information security management system (ISMS) implemented for over a year, NightCore contracted a certification body to perform an audit for ISO/IEC 27001 certification.
The certification body formed a team of five auditors, with Jack as a team leader. Jack is renowned for his extensive auditing experience in risk management, information security controls, and incident management. His skill set aligns well with the requirements of auditing principles and processes, enabling him to effectively comprehend the audit scope and apply relevant criteria effectively. Jack also demonstrates a solid understanding of NightCore's organizational structure, purpose, and management practices and the statutory and regulatory requirements applicable to its activities.
The audit carried out by the audit team followed a rational method to reach reliable and reproducible conclusions systematically. The audit team recognized that only information capable of being verified to some extent should be considered valid evidence. In some rare instances during the audit where the verification of certain information posed challenges and where its degree of verifiability was low, the auditors exercised their professional judgment to assess the reliability and determine the level of reliance that could be placed on such evidence.
During the audit, the auditors documented their observations and inspection notes regarding the operational planning and control of NightCore's ISMS operations. They also recorded observations of NightCore's inventory of information and associated assets. Additionally, the auditors reviewed the configuration of firewalls implemented to secure connections to network services.
As the audit approached its final stages, NightCore's commitment to upholding the highest levels of information security became evident. With ISO/IEC 27001 certification within reach, NightCore is well-positioned to achieve ISO/IEC 27001 certification, enhancing its reputation in the technology sector.
What type of audit did NightCore undergo?
NightCore underwent a third-party audit, making option C the correct answer. A third-party audit is conducted by an independent certification body for the purpose of assessing conformity against a recognized international standard, such as ISO/IEC 27001. This type of audit is required when an organization seeks formal certification.
In the scenario, NightCore explicitly contracted a certification body to perform an audit for ISO/IEC 27001 certification. The audit team was formed by the certification body, not by NightCore itself or by a customer or supplier. This independence is the defining characteristic of a third-party audit. The objective of such an audit is to determine whether the ISMS conforms to ISO/IEC 27001 requirements and whether certification can be granted.
Option A is incorrect because a first-party audit is an internal audit conducted by or on behalf of the organization itself. Although NightCore had conducted internal audits previously, the scenario clearly refers to a certification audit performed by an external body. Option B is incorrect because a second-party audit is conducted by an interested party, such as a customer auditing a supplier, which is not the case here.
Therefore, based on the involvement of an independent certification body and the goal of ISO/IEC 27001 certification, the audit conducted at NightCore is correctly classified as a third-party audit.
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services.
The next step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organisation outsourced the mobile app development to a professional software development organisation with CMMI Level 5, ITSM
(ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified.
The IT Manager presents the software security management procedure and summarises the process as follows:
The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum. The following security functions for personal data protection shall be available:
Access control.
Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and
Personal data pseudonymization.
Vulnerability checked and no security backdoor
You sample the latest Mobile App Test report - Reference ID: 0098, details as follows:


You would like to investigate other areas further to collect more audit evidence. Select three options that will not be in your audit trail.
The three options that will not be in your audit trail are A, C, and H. These options are either not relevant to the information security of ABC's healthcare mobile app development, support, and lifecycle process, or not within the scope of your audit. The amount of money that residents' family members pay to install the app (A) and the number of users of the app are not related to the information security aspects or objectives of the ISMS1. The verification of the developer's certifications (H) is not your responsibility as an ISMS auditor, as you should rely on the competence and impartiality of the certification bodies that issued them2. The other options are relevant and within the scope of your audit, as they relate to the security functions, testing, policies, and procedures of the mobile app development, support, and lifecycle process13. References: 1: ISO/IEC 27001:2022, Information technology --- Security techniques --- Information security management systems --- Requirements, Clause 4.2 \n2: ISO/IEC 27006:2022, Information technology --- Security techniques --- Requirements for bodies providing audit and certification of information security management systems, Clause 4.1 \n3: PECB Certified ISO/IEC 27001 Lead Auditor Exam Preparation Guide, Domain 5: Conducting an ISO/IEC 27001 audit
Scenario 3
NightCore, a multinational technology enterprise headquartered in the United States, specializes in e-commerce, cloud computing, digital streaming, and artificial intelligence (AI). After having an information security management system (ISMS) implemented for over a year, NightCore contracted a certification body to perform an audit for ISO/IEC 27001 certification.
The certification body formed a team of five auditors, with Jack as a team leader. Jack is renowned for his extensive auditing experience in risk management, information security controls, and incident management. His skill set aligns well with the requirements of auditing principles and processes, enabling him to effectively comprehend the audit scope and apply relevant criteria effectively. Jack also demonstrates a solid understanding of NightCore's organizational structure, purpose, and management practices and the statutory and regulatory requirements applicable to its activities.
The audit carried out by the audit team followed a rational method to reach reliable and reproducible conclusions systematically. The audit team recognized that only information capable of being verified to some extent should be considered valid evidence. In some rare instances during the audit where the verification of certain information posed challenges and where its degree of verifiability was low, the auditors exercised their professional judgment to assess the reliability and determine the level of reliance that could be placed on such evidence.
During the audit, the auditors documented their observations and inspection notes regarding the operational planning and control of NightCore's ISMS operations. They also recorded observations of NightCore's inventory of information and associated assets. Additionally, the auditors reviewed the configuration of firewalls implemented to secure connections to network services.
As the audit approached its final stages, NightCore's commitment to upholding the highest levels of information security became evident. With ISO/IEC 27001 certification within reach, NightCore is well-positioned to achieve ISO/IEC 27001 certification, enhancing its reputation in the technology sector.
According to Scenario 3, did the auditors appropriately handle information that could only be verified to some extent?
The auditors handled partially verifiable information appropriately by applying professional judgment, which makes option A the correct answer. ISO 19011:2018 emphasizes that auditing is not a purely mechanical process and requires auditors to apply due professional care when evaluating evidence. Audit evidence is often based on samples and may vary in its degree of verifiability. The key requirement is that auditors assess the reliability, relevance, and sufficiency of the evidence before using it to support audit conclusions.
In the scenario, the audit team explicitly recognized that some information could only be verified to a limited extent and responded by carefully evaluating how much reliance could be placed on that information. This aligns with ISO 19011 principles, particularly the evidence-based approach and due professional care. Auditors are expected to exercise judgment when full verification is impractical, provided they clearly understand the limitations of the evidence and do not overstate its reliability.
Option B is incorrect because ISO standards do not require auditors to discard all partially verifiable information. Doing so could lead to incomplete audit conclusions and an unrealistic audit process. Option C is also incorrect because while external experts may be used in certain specialized cases, ISO 19011 does not mandate their involvement whenever evidence is difficult to verify. The auditors' approach in the scenario demonstrates appropriate competence and professional judgment, consistent with ISO auditing guidance.
To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team studied a sample of server logs to determine if they could be edited or deleted. Which audit procedure did the audit team use?
The audit team used technical verification, making option B the correct answer. Technical verification involves examining technical configurations, system settings, or operational characteristics of information systems to verify whether controls are implemented and effective. In this scenario, the auditors examined server logs to determine whether they could be altered or deleted, which directly assesses the technical enforcement of logging controls.
ISO/IEC 27002:2022 control 8.15 requires organizations to ensure that logs are protected against unauthorized modification or deletion. Verifying this requirement cannot be achieved through interviews or documentation alone; it requires direct interaction with or inspection of the technical system.
Option A is incorrect because analysis refers to evaluating information, patterns, or results after evidence has been collected, not to the act of examining system configurations. Option C is incorrect because observation involves watching activities or processes being performed, such as monitoring staff behavior or physical security practices, not inspecting system-level controls.
Therefore, reviewing server logs for editability or deletion capability is a clear example of technical verification, which is an appropriate and necessary audit procedure for technological controls.
Which two of the following phrases would apply to "audit objectives"?
The audit objectives are the purpose and scope of an audit, as defined by the audit client and the auditor.According to the ISO/IEC 27001 standard, the audit objectives for an ISMS audit may include determining the extent of conformity of the ISMS with the audit criteria, evaluating the ability of the ISMS to ensure the organization meets its information security objectives, and identifying potential areas for improvement of the ISMS12.References: =1: PECB Candidate Handbook - ISO/IEC 27001 Lead Auditor, page 192: ISO/IEC 27007:2011 Information technology --- Security techniques --- Guidelines for information security management systems auditing, clause 4.2.1.
Emma Morris
6 days agoAngela Phillips
14 days agoTiffany Green
1 month agoRonald Baker
2 months agoJohn Howard
2 months agoSarah Peterson
3 months agoGary Moore
3 months agoNancy Allen
4 months agoThomas Adams
3 months agoKevin Torres
3 months agoKenneth Moore
3 months agoAndrew Taylor
3 months agoRachel Hernandez
3 months agoKris
4 months agoDiego
5 months agoJani
5 months agoSabrina
5 months agoJoesph
5 months agoHector
6 months agoJettie
6 months agoMammie
6 months agoTwanna
6 months agoAudry
7 months agoBettina
7 months agoShonda
7 months agoLaurel
8 months agoLeatha
8 months agoPeggie
8 months agoAlida
8 months agoFrank
8 months agoLera
9 months agoBette
9 months agoYoko
9 months agoWillodean
10 months agoJames
10 months agoIsaiah
10 months agoMarsha
10 months agoMarvel
11 months agoNan
11 months agoFranchesca
11 months agoNelida
11 months agoStephania
11 months agoLoren
1 year agoLashaun
1 year agoTina
1 year agoGearldine
1 year agoAileen
1 year agoLai
2 years agoTwanna
2 years agoAngelica
2 years agoPaz
2 years agoBernardo
2 years agoJulie
2 years agoElfriede
2 years agoCarmelina
2 years agoLouann
2 years agoBarabara
2 years agoJaney
2 years agoRoselle
2 years agoZachary
2 years agoEmeline
2 years agoLisandra
2 years agoJulio
2 years agoMy
2 years agoVi
2 years agoGlynda
2 years agoStephen
2 years agoJody
2 years agoSusy
2 years agoOnita
2 years agoHarrison
2 years agoTori
2 years agoReuben
2 years ago