NEW
Font size
WorksheetsTambahan soal Lead Auditor
Total questions: 25
Worksheet time: 13mins
What step should an auditor follow to ensure the competence of staff in outsourced operations?
Review the service provider’s processes and employees’ contracts
Ensure that disaster recovery processes are in place
Review and evaluate the organization’s plan in case of an unexpected termination of the outsourcing agreement
Which services can be managed by the user when using Platform as a Service (PaaS)?
Virtualization and servers
Runtime and middleware
Application and data
Audit evidence must be:
Verifiable
Physical
Reputable
What type of evidence is an external audit report?
Physical
Confirmative
Analytical
How can an auditor verify conformity to control 5.18 Access rights of ISO/IEC 27001 by using analytical evidence?
By analyzing results of the access rights removal procedure on a sample of users upon the termination of their contracts
By analyzing the removal or adjustment of access rights procedure
By analyzing the access rights removal simulation test
What makes audit evidence appropriate?
Sufficiency
Relevance and reliability
Approval
Which type of audit risk is known as the risk that occurs in the management system despite the internal control mechanisms in an organization?
Inherent risk
Control risk
Detection risk
Which of the following factors should be considered when determining the materiality of a system?
The organizational changes
The conditions of service-level agreements
The audit results
Materiality is taken into account to determine the duration of the audit based on the risks inherent to the organization during:
Initial contact
Stage 1 audit
Stage 2 audit
What does “control risk” mean?
The risk that a significant defect related to the organizations’ internal controls could not be detected by the auditor
The risk that a significant defect could not be prevented by the organization’s internal control mechanisms
The risk that remains after a significant defect of an internal control is detected and corrected
What action is taken during stage 1 audit when evaluating materiality during the audit?
Identifying the key processes to be audited
Determining the audit duration
Adjusting the plan based on the materiality of each process or asset
Which parties are involved in an audit offer?
The auditor and the auditee
The certification body and the auditee
The certification body and the auditor
What can trigger the initiation of a change in the audit scope?
Recent changes in the existing processes
Review of major information security incidents
Modifications in the information security policy
Auditors use the _______________ as a reference to determine conformity.
Audit feasibility
Audit Criteria
Audit objectives
The lead auditor evidences that in the previous audit a nonconformity applicable to information security policies was declared and for this year the same situation is still occurring, which clause of ISO 27001:2022 is being breached with a clear failure to follow up?
5.3.
5.2.
10.2.
5.1.
Reporting to senior management on the performance of the ISMS is an assigned responsibility:
Senior Management.
The leader of each process.
Management of the organization.
The information security leader.
A laptop was stolen from a hotel where the information security officer was lecturing. Which control of ANNEX A of ISO IEC 27001:2022 should or must this PC have had?
A.7.8.
A. 5.10.
A. 5.1.
A. 7.9.
The lead auditor evidences that risk acceptance criteria are not yet established, which clause of ISO 27001:2022 is being breached?
6.1.2.
9.1.
8.3
5.1
The basis for audit impartiality and objectivity of audit findings is:
An element for the presentation of the audit scope.
An element for decision making in information security risks.
An element for the presentation of the audit report.
A principle of auditing.
Once the audit has been carried out, the auditor in charge of the audit must
prepare the Audit Report. This report establishes:
a. Audit objectives
b. Scope of the audit.
c. Auditees and the audit period.
d. Documentation of the contact person.
e. Documentation of the lead auditor and other auditors.
f. Dates and locations where the audit activities took place.
g. Audit criteria.
h. Audit statements.
i. Audit Conclusions.
All are correct.
Only i.
All except d and e.
It establishes that the organization must implement the risk treatment
process:
a) Clause 6.1.2
b) Clause 6.1.3
c) Clause 8.3
d) B and C are valid
According to ISO 19011:2018, audit criteria are:
They are related in detail in the audit report.
A set of requirements used as a reference against which objective evidence is compared.
Detailed by the auditor in conjunction with the Company and the audited process.
Only known to the Company's senior management and the auditor.
An auditor should declare a NON-COMPLIANCE, when:
The Organization decides to exclude clause 5.3 Roles, Responsibilities and Authorities in the Organization.
The Organization decides to exclude control 7.1 Physical security perimeters.
The Organization decides to exclude control 6.7 Remote work.
The Organization decides to exclude control 8.27 Secure architecture and security principles for information systems.
ISO 19011:2018 defines the need for resource related risk assessment. An example of a resource related risk is:
Ineffective external/internal communication processes/channels.
Failure to establish the relevant audit objectives and determine the scope, number, duration, locations, and timing of audits.
Insufficient overall competence to perform audits effectively.
Allowing insufficient time, equipment and/or training to develop the audit program or conduct an audit.
Perceptive, diplomatic, and versatile are:
Personal attributes of the person(s) managing the audit program.
Personal attributes of the auditors.
Personal capabilities that senior management should have.
Personal attributes of the auditees.
