Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 27 Topic 3 Discussion

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 27 Topic 3 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 3 Question 27 Discussion:
Question #: 27
Topic #: 3

You are an experience ISMS audit team leader carrying out a third-party certification audit of an organization specialising in the secure disposal of confidential documents and removable media. Both documents and media are shredded in military grade devices which make it impossible to reconstruct the original.

The audit has gone well and you are just about to start to write the audit report, 30 minutes before the closing meeting. At

this point one of the organization's employees knocks on your door and asks if they can speak to you. They tell you that when things get busy her manager tells her to use a lower grade industrial shredder instead as the organisation has more of these and they operate faster. You were not informed about the existence or use of these machines by the auditee.

Select three options for how you should respond to this information.


A.

Advise the individual managing the audit programme of any recommendation by you to conduct a further auditprior to certification


B.

Cancel the production of the audit report and instead review the organization's contracts with its clients to determine whether they have permitted the use of lower grade machines


C.

Consider the need for a subsequent audit within 4 weeks based on the additional information that has come to light


D.

Do nothing. All audits are based on a sample and the sample you took did not include a planned review of the lower grade machines


E.

Extend the certification audit duration to create additional time to audit the use of the lower grade machines


F.

Raise a nonconformity against 8.1 Operational Planning and Control as the organization has not been open about its processes


G.

Verify with the auditee that lower grade machines are used in certain circumstances


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.