PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 51 Topic 6 Discussion

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 51 Topic 6 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 6 Question 51 Discussion:
Question #: 51
Topic #: 6

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded the marketing division from the audit scope, although they stated in their ISMS scope that the whole company is included. Is this acceptable?


A.

Yes, audit and ISMS scope do not necessarily need to be the same


B.

No, divisions that are not critical for the industrial sector in which the auditee operates can be excluded from the audit scope


C.

No, audit scope should reflect all of the organization’s divisions covered by the ISMS


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.