Scenario Based Lead Auditor Day#4

Scenario Based Lead Auditor Day#4

1st Grade

5 Qs

quiz-placeholder

Similar activities

Forecast & ES 小博士

Forecast & ES 小博士

1st Grade

10 Qs

Scenario Based Lead Auditor Day#2

Scenario Based Lead Auditor Day#2

1st Grade

5 Qs

Auditing Major Projects

Auditing Major Projects

KG - Professional Development

10 Qs

INTERNAL AUDIT ISO 14001 SISTEM MANAJEMEN LINGKUNGAN

INTERNAL AUDIT ISO 14001 SISTEM MANAJEMEN LINGKUNGAN

1st - 3rd Grade

10 Qs

Pre Test PKS Konsep dan Perencanaan Probity Audit

Pre Test PKS Konsep dan Perencanaan Probity Audit

1st - 12th Grade

10 Qs

Ch-4 Laporan Auditor Independen (LAI)

Ch-4 Laporan Auditor Independen (LAI)

1st Grade - Professional Development

10 Qs

Scenario-based Quiz 4

Scenario-based Quiz 4

1st Grade

5 Qs

RSPO

RSPO

1st - 10th Grade

10 Qs

Scenario Based Lead Auditor Day#4

Scenario Based Lead Auditor Day#4

Assessment

Quiz

Professional Development

1st Grade

Hard

Created by

sudiyuwono wowo

FREE Resource

5 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Company ABC is a leading software development and testing company headquartered in Frankfurt, Germany offering services based on the clients’ requests and needs. The development process is divided into the following phases: discovery, development, testing, deployment, and maintenance. During each phase, the company ensures information privacy and protection through a successfully implemented and maintained ISMS.

 

However, the ISMS implementation alone could not help them expand their market. That is why they decided to apply for an ISO/IEC 27001 certification.

 

The company contacted a certification body to undergo the process of certification. You, an auditor that works for the certification body, are selected as the audit team leader. During the course of audit activities, you draft the audit findings and the nonconformity reports.

 

Upon considering the validity of the audit evidence, you drafted two nonconformity reports for the detected nonconformities. The reports followed the same structure: the audit criteria, description of the observed nonconformity, and the audit finding.

 

Based on the audit findings and other information collected during the audit, you recommend Company ABC for certification upon the filing of corrective action plans. The audit conclusion was discussed with the auditee’s representatives, who ensured you that action plans will be submitted as soon as possible.

 

To resolve the first detected nonconformity, Company ABC submitted the following action plan: “A formal user registration and de-registration process to grant or deny access to systems and services that process sensitive information will be created.” The action plan addressing the second nonconformity stated that “A new version of the security policy will be published to include legal and regulatory requirements.”

 Once the submitted action plans and the implemented corrective actions were evaluated, you decide to close the detected nonconformities.

 Answer the following questions by referring to the above-mentioned scenario:

What should have you taken into consideration, in addition to the audit evidence, when determining the audit findings?

Requirements of the audit client

Submission of corrective actions

Content of action plans

Answer explanation

When determining audit findings, the requirements of the audit client should be considered, among others.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

You have validated the action plans and the implemented corrective actions submitted by Company ABC. What type of audit have you conducted?

Surveillance audit

Audit follow-up

Internal audit

Answer explanation

The objective of an audit follow-up is to validate the action plans and the implemented corrective actions submitted by the auditee.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following statements presents the best description of the observed nonconformity related to the first action plan submitted by Company ABC?

The process used to grant or deny access to systems and services that process sensitive information is not documented

There is no process in place to manage access to systems and services that process sensitive information

In a sample of 30 user accounts belonging to former employees of Company ABC, only 5 of them followed the formal user de-registration process

Answer explanation

Options A and C are incorrect because they refer to a user registration and de-registration process not being used properly. The key word “has been created used in the action plan indicates that Company ABC did not have such process in place.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The auditee has submitted the following action plan, “A formal user registration and de-registration process to grant or deny access to systems and services that process sensitive information will be created.” Is this action plan acceptable?

No, because it does not address the root cause of the detected nonconformity

No, because a time frame for completing the action has not been included

No, because the required resources for the implementation have not been included

Answer explanation

The auditee is required to submit a general statement regarding the actions to be taken to treat nonconformities, including a time frame for completing the action.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What type of audit finding does the second action plan resolve?

Anomaly

Major nonconformity

Minor nonconformity

Answer explanation

The second action plan shows that a security policy exists but does not include legal and regulatory requirements. Hence, the policy does fulfill the requirements partially and presents a minor nonconformity.