ISO-IEC-27001-Lead-Auditor-CN Exam Info and Free Practice Test Professional Quiz Study Materials [Q176-Q192]

Share

ISO-IEC-27001-Lead-Auditor-CN Exam Info and Free Practice Test Professional Quiz Study Materials

Accurate Hot Selling ISO-IEC-27001-Lead-Auditor-CN Exam Dumps 2026 Newly Released

NEW QUESTION # 176
場景 6:Cyber​​ ACrypt 是一家網路安全公司,透過提供反惡意軟體和設備安全、資產生命週期管理和設備加密來提供端點保護。為了根據 ISO/IEC 27001 驗證其 ISMS 並證明其對網路安全卓越的承諾,該公司經歷了由指定審計團隊負責人 John 領導的細緻的審計過程。
在接受審計任務後,John 立即組織了一次會議,概述了審計計劃和團隊角色。他們審查了 Cyber​​ ACrypt 的文檔信息,包括資訊安全政策和操作程序,確保每一份文件都符合標準並具有標準化的格式,包括作者標識、生產日期、版本號和批准日期。這次徹底的檢查旨在確定持續改進和遵守 ISMS 要求。該文件對於審計團隊和 Cyber​​ ACrypt 了解初步審計結果和需要關注的領域至關重要。
審計組也決定對主要相關方進行訪談。這項決定的目的是收集可靠的審計證據來驗證管理系統是否符合 ISO/IEC 27001 的要求。與 Cyber​​ ACrypt 各個層級的相關方進行接觸為審計團隊提供了寶貴的觀點以及對 ISMS 的實施和有效性的理解。
第一階段審計報告揭露了值得關注的關鍵領域。適用性聲明 (SoA) 和 ISMS 政策在多個方面存在缺陷,包括風險評估不足、存取控制不充分以及缺乏定期政策審查。這促使 Cyber​​ ACrypt 立即採取行動來解決這些缺陷。他們對戰略文件的快速回應和修改體現出了對實現合規的堅定承諾。
為了彌補審計團隊的網路安全知識差距而引入的技術專長在識別風險評估方法中的缺陷和審查網路架構方面發揮了關鍵作用。這包括評估防火牆、入侵偵測和預防系統以及其他網路安全措施,以及評估 Cyber​​ ACrypt 如何偵測、回應和恢復外部和內部威脅。在約翰的監督下,技術專家將審計結果傳達給了 Cyber​​ ACrypt 的代表。然而,審計小組發現,由於收取了被審計單位的諮詢費,該專家的客觀性可能受到影響。考慮到技術專家在審核過程中的行為,審核組長決定與認證機構討論這個問題。
根據上述情景,回答以下問題:
根據場景 6,Cyber​​ ACrypt 在第 1 階段審計報告之後修改了 SoA 和 ISMS 政策。您如何定義這種情況?

  • A. 不可接受,一旦外部審核通過第 1 階段,SoA 和 ISMS 政策就無法修改
  • B. 可接受,應糾正第二階段審核期間導致重大不符合的情況
  • C. 在提交最終審計報告之前,可以對 SoA 和 ISMS 政策進行可接受的微小修改

Answer: B

Explanation:
Comprehensive and Detailed In-Depth
B . Correct Answer:
Stage 1 audits identify gaps and allow the organization to correct major nonconformities before Stage 2 certification.
ISO/IEC 27006 requires organizations to address major nonconformities before proceeding to Stage 2.
A . Incorrect:
Organizations are allowed to correct nonconformities identified in Stage 1.
C . Incorrect:
Major changes must be addressed, not just minor modifications.
Relevant Standard Reference:
ISO/IEC 27006:2020 Clause 9.2.3 (Stage 1 and Stage 2 Audit Process)


NEW QUESTION # 177
資料完整性意味著

  • A. 資料只能由適當的人存取
  • B. 資料應始終可見
  • C. 資料的準確性和完整性

Answer: C

Explanation:
Integrity of data means accuracy and completeness of the data. Integrity is one of the three main objectives of information security, along with confidentiality and availability. Integrity ensures that information and systems are not corrupted, modified, or deleted by unauthorized actions or events. Data should be viewable at all times is not related to integrity, but to availability. Data should be accessed by only the right people is not related to integrity, but to confidentiality. References: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 24. : [ISO/IEC 27001 Brochures | PECB], page 4.


NEW QUESTION # 178
下列哪一項是利害關係方的定義?

  • A. 可以控制決策或活動、被決策或活動控製或認為自己被決策或活動控制的個人或組織
  • B. 可以乾擾管理決策或認為自己受到管理決策幹擾的團體或組織
  • C. 當第三人認為自己受到決策或活動的影響時,可以向組織提出申訴
  • D. 可以影響決策或活動、受決策或活動影響或認為自己受決策或活動影響的個人或組織

Answer: D

Explanation:
This is the definition of an interested party according to ISO 27001:2013, clause 3.16. An interested party is essentially a stakeholder, i.e., a person or organization that can influence or be influenced by the information security management system (ISMS) or its activities. Interested parties can have different needs and expectations regarding the ISMS, and these should be identified and addressed by the organization. Reference:
ISO/IEC 27001:2013, Information technology - Security techniques - Information security management systems - Requirements, clause 3.16 PECB Candidate Handbook ISO 27001 Lead Auditor, page 10 Identifying interested parties and their expectations for an ISO 27001 ISMS Examples of ISO 27001 interested parties


NEW QUESTION # 179
您詢問 IT 經理,為什麼組織仍在使用行動應用程序,而個人資料加密和假名化測試卻失敗了。此外,服務經理是否有權批准測試。
IT經理解釋說,根據軟體安全管理程序,測試結果應由他批准。加密和假名功能失敗的原因是這些功能嚴重降低了系統和服務效能。需要額外 150% 的資源來滿足這一點。服務經理同意存取控制足夠好並且可以接受。這就是服務經理簽署批准書的原因。
您對醫務人員的手機進行採樣,發現安裝了 ABC 的醫療保健移動應用程序,版本 1.01。你發現1.01版本沒有測試記錄。
IT經理解釋說,由於勒索軟體攻擊頻繁,外包行動應用開發公司對受測軟體進行了免費小幅更新,並對更新後的軟體進行了緊急發布,並口頭保證不會對安全造成任何影響。
以他20年的資訊安全經驗來看,沒有必要重新測試。
您正在準備審核結果 請選擇兩個正確的選項。

  • A. 不存在不合格項 (NC)。 IT 經理證明他完全有能力。 (與第7.2條相關)
  • B. 存在不合格項 (NC)。組織不控制計劃的變更並審查非預期變更的後果。 (與第8.1條相關)
  • C. 還有改進的機會 (OI)。 IT 經理應根據適當的測試做出是否繼續提供服務的決定。 (與第 8.1 條相關,控制措施 A.8.30)
  • D. 還有改進的機會 (OI)。該組織根據其提供的免費服務的範圍選擇外部服務提供者。 (與第 8.1 條相關,控制措施 A.5.21)
  • E. 存在不合格項 (NC)。 IT 經理不遵守軟體安全管理程序。 (與第 8.1 條相關,控制措施 A.8.30)
  • F. 不存在不合格項 (NC)。 IT 經理展現了良好的領導能力。 (與條款相關
    5.1,控制5.4)

Answer: B,E

Explanation:
According to ISO 27001:2022 Annex A Control 8.30, the organisation shall ensure that externally provided processes, products or services that are relevant to the information security management system are controlled. This includes developing and entering into licensing agreements that cover code ownership and intellectual property rights, and implementing appropriate contractual requirements related to secure design and coding in accordance with Annex A 8.25 and 8.2912 In this case, the organisation and the developer have performed security tests that failed, which indicates that the secure design and coding requirements of Annex A 8.29 were not met. The IT Manager explains that the encryption and pseudonymization functions failed because they slowed down the system and service performance, and that an extra 150% of resources are needed to cover this. However, this does not justify the acceptance of the test results by the Service Manager, who is not authorised to approve the test according to the software security management procedure. The Service Manager should have consulted with the IT Manager, who is the owner of the process, and followed the procedure for handling nonconformities and corrective actions. The Service Manager's decision to continue the service based on access control alone exposes the organisation to the risk of compromising the confidentiality, integrity, and availability of personal data processed by the mobile app. Therefore, there is a nonconformity (NC) with clause 8.1, control A.8.30.
According to ISO 27001:2022 Clause 8.1, the organisation shall plan, implement and control the processes needed to meet information security requirements, and to implement the actions determined in Clause
6.1. The organisation shall also control planned changes and review the consequences of unintended changes, taking action to mitigate any adverse effects, as necessary12 In this case, the organisation has not controlled the planned change of the mobile app from version 1.0 to version 1.01, which was a minor update provided by the outsourced developer in response to frequent ransomware attacks. The IT Manager explains that the developer performed an emergency release of the updated software, and gave a verbal guarantee that there will be no impact on any security functions.
However, this is not sufficient to ensure that the change is properly assessed, tested, documented, and approved before deployment. The IT Manager should have followed the change management process and procedure, and verified that the updated software meets the security requirements and does not introduce any new vulnerabilities or risks. The IT Manager's reliance on his 20 years of information security experience and the developer's verbal guarantee is not a valid basis for skipping the re-testing of the software. Therefore, there is a nonconformity (NC) with clause 8.1.
References:
1: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Course by CQI and IRCA Certified Training 1 2: ISO/IEC 27001 Lead Auditor Training Course by PECB 2


NEW QUESTION # 180
下列哪兩個選項不參與 ISO/IEC 27001 的第二方審核?

  • A. 接受過 CQI 和 IRCA 計畫訓練的審核員
  • B. 由審核員認證機構認證的審核員
  • C. 客戶的內部稽核員
  • D. 來自認證機構的審核員
  • E. 外部諮詢機構聘用的審核員
  • F. 認證機構聘用的審核員

Answer: A,D

Explanation:
*Second-Party Audits: These involve an organization (the customer) auditing another organization with which it has a relationship (such as a supplier). The focus is on ensuring the supplier meets the customer's information security requirements.
*Accreditation Bodies: These assess the competence of certification bodies but don't directly participate in second-party audits.
*CQI and IRCA: These organizations provide auditor certifications but their training alone doesn't automatically qualify someone for second-party ISO/IEC 27001 audits. The auditor should have specific knowledge of the standard.
References:
*ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems: Provides requirements for certification bodies but also outlines how first-, second-, and third-party audits work.
*PECB Candidate Handbook, ISO/IEC 27001 Lead Auditor: Explains the distinctions between first, second, and third-party audits, clarifying that second-party audits are usually between organizations with a prior relationship.


NEW QUESTION # 181
CEO發送一封電子郵件,表達他對公司現狀和公司未來策略的看法以及CEO的願景和員工在其中的角色。郵件應分類為

  • A. 公共郵件
  • B. 受限郵件
  • C. 機密郵件
  • D. 內部郵件

Answer: D

Explanation:
The mail sent by the CEO giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it should be classified as internal mail. Internal mail is a type of classification that indicates that the information is intended for internal use only, and should not be disclosed to external parties without authorization. The mail sent by the CEO contains information that is relevant and important for the employees of the company, but may not be suitable for public disclosure, as it may contain sensitive or confidential information about the company's performance, goals, or plans. References: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 34. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 37. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 14.


NEW QUESTION # 182
下列哪一項最能描述第二階段審核的目的?

  • A. 檢查組織是否遵守法律
  • B. 評估管理系統的實施情況
  • C. 確保審核計畫得到執行
  • D. 了解組織的流程

Answer: B

Explanation:
The purpose of a Stage 2 audit is to evaluate the implementation of the management system, in this case, the ISMS, according to the requirements of ISO/IEC 27001:2022 and the organisation's own policies and procedures. The Stage 2 audit involves collecting evidence of the effectiveness and performance of the ISMS, as well as verifying the conformity and suitability of the organisation's controls. The Stage 2 audit also assesses the organisation's ability to achieve its information security objectives and to manage information security risks. References: = ISO/IEC 27006:2022, clause 9.2.2.2; PECB Candidate Handbook ISO 27001 Lead Auditor, page 28.


NEW QUESTION # 183
身為稽核員,您注意到 ABC Inc. 已經建立了管理可移動儲存媒體的程式。該程式基於 ABC Inc. 採用的分類方案。但是,公開資訊沒有保密性要求,因此只適用完整性和可用性控制。這是什麼類型的審計發現?

  • A. 不符合
  • B. 一致
  • C. 異常

Answer: B

Explanation:
Comprehensive and Detailed In-Depth
C . Correct Answer:
The classification-based security approach aligns with ISO/IEC 27001:2022 Annex A Control A.5.12 (Classification of Information).
The organization is applying a security control in accordance with the classification policy, ensuring conformity to information security best practices.
A . Incorrect:
Nonconformity occurs when a process does not comply with ISO/IEC 27001 requirements. However, in this case, the classification system is correctly implemented.
B . Incorrect:
Anomaly refers to unexpected deviations in operations, but this is an intentional implementation.
Relevant Standard Reference:


NEW QUESTION # 184
當審核團隊的另一位成員向您尋求澄清時,您正在進行第三方監督審核。他們被要求評估組織對控制 5.7 - 威脅情報的應用。他們知道這是 2022 年版 ISO/IEC 中引入的新控制措施之一
27001,他們希望確保正確審核控制。
他們準備了一份清單來協助他們進行審核,並希望您確認他們計劃的活動符合控制要求。
下列哪三個選項代表有效的審計追蹤?

  • A. 我將確定在威脅情報的生成中是否使用內部和外部資訊來源
  • B. 我將確保將產生威脅情報的任務分配給組織的內部稽核團隊
  • C. 我將確保採取適當措施,向最高管理階層通報目前威脅情報安排的有效性
  • D. 我將回顧如何收集和評估與資訊安全威脅相關的資訊以產生威脅情報
  • E. 我將檢查該組織是否擁有完整記錄的威脅情報流程
  • F. 我將確保組織的風險評估流程從有效的威脅情報開始
  • G. 我將與高階主管交談,以確保所有員工都意識到報告威脅的重要性
  • H. 我將檢查是否積極使用威脅情報來保護組織資訊資產的機密性、完整性和可用性

Answer: C,D,H

Explanation:
These three options represent valid audit trails for control 5.7, as they are aligned with the control's requirements and objectives. According to the web search results from my predefined tool, control 5.7 requires organisations to collect and analyse information relating to information security threats and use that information to take mitigation actions12. The control also specifies that threat intelligence should be relevant, perceptive, contextual, and actionable, and that it should be used to prevent, detect, or respond to threats34. Therefore, the auditor should verify how the organisation collects, analyses, and produces threat intelligence, how it uses threat intelligence to protect its information assets, and how it monitors and evaluates the effectiveness of its threat intelligence arrangements. The other options are not valid audit trails, as they are either irrelevant, incorrect, or incomplete. For example:
* The task of producing threat intelligence is not assigned to the organisation's internal audit team, but to the person or team responsible for the ISMS, such as the information security manager or the information security committee5 .
* The organisation's risk assessment process does not begin with effective threat intelligence, but with the identification of the context, scope, and objectives of the ISMS . Threat intelligence is an input for the risk identification and analysis, but not the starting point of the risk assessment process.
* Speaking to top management to make sure all staff are aware of the importance of reporting threats is not sufficient to audit the control, as it does not address how the organisation collects, analyses, and produces threat intelligence, nor how it uses it to take mitigation actions. The auditor should also speak to the staff involved in the threat intelligence process, and review the relevant documents and records.
* Checking that the organisation has a fully documented threat intelligence process is not enough to audit the control, as it does not verify the implementation and effectiveness of the process. The auditor should also observe the process in action, and examine the outputs and outcomes of the process.
* Determining whether internal and external sources of information are used in the production of threat intelligence is a partial audit trail, as it only covers one aspect of the control. The auditor should also assess the quality, reliability, and relevance of the sources, and how the information is analysed and used.


NEW QUESTION # 185
以下是資訊安全的目的,但以下情況除外:

  • A. 增加企業資產
  • B. 最大化投資回報
  • C. 最小化業務風險
  • D. 確保業務連續性

Answer: A

Explanation:
The following are purposes of information security, except increasing business assets. Increasing business assets is not a purpose of information security, as it is not directly related to protecting information and systems from threats and risks. Information security may contribute to increasing business assets by enhancing customer trust, reputation, compliance, and efficiency, but it is not its primary goal. Ensuring business continuity is a purpose of information security, as it aims to prevent or minimize disruptions or losses caused by incidents affecting information and systems. Minimizing business risk is a purpose of information security, as it aims to identify and reduce threats and vulnerabilities that may compromise information and systems. Maximizing return on investment is a purpose of information security, as it aims to optimize the costs and benefits of implementing and maintaining information security controls and measures. References: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 23. : [ISO/IEC
27001 Brochures | PECB], page 4.


NEW QUESTION # 186
您正在對位於歐洲的住宅進行 ISMS 審核
名為 ABC 的療養院提供醫療保健服務。您會發現所有療養院居民都戴著電子腕帶,用於監控他們的位置、心跳和血壓。您了解到,電子腕帶會自動將所有資料上傳到人工智慧(AI)雲端伺服器,供醫護人員進行健康監測和分析。
審核計畫的下一步是驗證高階管理人員是否已製定資訊安全策略和目標。
在審計過程中,你們發現以下審計證據。
將審核證據與 ISO/IEC 27001:2022 中的相應要求進行配對。

Answer:

Explanation:


NEW QUESTION # 187
目標、標準和範圍是第三方 ISMS 審核的關鍵特徵。哪兩個問題是審計目標?

  • A. 評估是否符合 ISO/IEC 27001 要求
  • B. 確定 ISMS 的範圍
  • C. 評估客戶流程與功能
  • D. 檢討組織效率
  • E. 完成審核計劃
  • F. 確認執行 ISMS 的站點

Answer: A,F

Explanation:
Audit objectives are the specific purposes or goals that the customer or the certification body wants to achieve through the audit. They define what the audit intends to accomplish and provide the basis for planning and conducting the audit. Audit objectives may vary depending on the type, scope, and criteria of the audit, but they should be clear, measurable, and achievable.
Some examples of audit objectives for a third-party ISMS audit are:
Assess conformity with ISO/IEC 27001 requirements: This objective means that the audit aims to verify that the organisation's ISMS meets the requirements of the ISO/IEC 27001 standard, which specifies the best practices for establishing, implementing, maintaining, and improving an information security management system. The audit will evaluate the organisation's ISMS documentation, processes, controls, and performance against the standard's clauses and annex A controls.
Confirm sites operating the ISMS: This objective means that the audit aims to confirm that the organisation's ISMS covers all the relevant sites or locations where the organisation operates or provides its services. The audit will verify that the scope of the ISMS is accurate and consistent with the organisation's context, objectives, and risks.
The other phrases are not audit objectives, but rather:
Evaluate customer processes and functions: This is not an audit objective, but rather a possible audit criterion or a requirement that the organisation's processes and functions should meet. The audit criterion is the reference against which the audit evidence is compared to determine conformity or nonconformity. The audit criterion may include ISO/IEC 27001 requirements, customer requirements, or other applicable standards or regulations.
Fulfil the audit plan: This is not an audit objective, but rather a task or an activity that the auditor performs during the audit. The audit plan is a document that describes the arrangements and details of the audit, such as the objectives, scope, criteria, schedule, roles, and responsibilities. The auditor should follow and fulfil the audit plan to ensure that the audit is conducted effectively and efficiently.
Determine the scope of the ISMS: This is not an audit objective, but rather a prerequisite or an input for conducting the audit. The scope of the ISMS is the extent and boundaries of the information security management system within the organisation. It defines what processes, activities, locations, assets, and stakeholders are included or excluded from the ISMS. The scope of the ISMS should be determined by the organisation before applying for certification or undergoing an audit.
Review organisation efficiency: This is not an audit objective, but rather a possible outcome or a result of conducting an audit. The organisation efficiency is a measure of how well the organisation uses its resources to achieve its goals and objectives. The audit may help review and improve the organisation efficiency by identifying strengths, weaknesses, opportunities, and threats in its information security management system.
Reference:
ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) objectives and content from Quality.org and PECB ISO 19011:2018 Guidelines for auditing management systems [Section 5.3.1]


NEW QUESTION # 188
您是一位經驗豐富的 ISMS 審核團隊負責人,目前正在對新客戶進行第三方初始認證審核,使用 ISO/IEC 27001:2022 作為標準。
這是為期兩天的審計的第二天下午,您正要開始撰寫審計報告。到目前為止還沒有發現任何不符合項,而且您和您的團隊對該網站和組織的資訊安全管理系統印象深刻。
此時,您的團隊中的一名成員找到您並告訴您,她無法完成對領導力和承諾的評估,因為她花了太長時間審查變更計劃。
針對此訊息,您將採取下列哪一種行動?

  • A. 鑑於未發現任何不符合項,且組織的整體印象良好,請在審核報告中記錄積極的認證建議。
  • B. 向客戶道歉並告訴他們您將稍後回來審查領導能力和承諾。
  • C. 告知受審計方和審計客戶目前無法做出積極的建議。
  • D. 聯絡管理審計計劃的個人並尋求他們的許可,在審計報告中記錄積極的建議。
  • E. 聯絡您的總部並等待他們關於如何進行的進一步指示。
  • F. 通知受審核方需要​​終止並重新安排認證審核。
  • G. 向客戶建議,如果他們準備將您的回程航班升級為頭等艙,您將明天在自己的時間內審核領導力和承諾。

Answer: C

Explanation:
Review the audit plan and client availabilities to determine whether there is any opportunity for another member of your team to pick up this task before the closing meeting.
Explanation:
Leadership and commitment is a key requirement of ISO/IEC 27001:2022, as it establishes the top management's role and responsibility in establishing, implementing, maintaining, and continually improving the ISMS. Without assessing this aspect, the audit team cannot conclude that the ISMS is effective and conforms to the standard. Therefore, the audit team leader should advise the auditee and audit client that it is not possible to make a positive recommendation at this point, and explain the reason and the implications. The audit team leader should also consult with the certification body and the audit programme manager on the next steps, such as extending the audit duration, conducting a follow-up audit, or issuing a conditional certification, depending on the certification body's policy and the audit client's agreement. Reference: = ISO/IEC 27001:2022, clause 5, Leadership PECB Candidate Handbook ISO 27001 Lead Auditor, page 19, Audit Process PECB Candidate Handbook ISO 27001 Lead Auditor, page 22, Audit Report PECB Candidate Handbook ISO 27001 Lead Auditor, page 23, Audit Conclusion and Recommendation


NEW QUESTION # 189
以下是保護您的密碼的準則,但以下情況除外:

  • A. 為了方便回憶,公司和個人帳號使用相同的密碼
  • B. 不同公司係統安全存取不要使用相同的密碼
  • C. 不要與任何人分享密碼
  • D. 首次登入時變更暫時密碼

Answer: A,C

Explanation:
The following are guidelines to protect your password, except for easy recall use the same password for company and personal accounts; do not share passwords with anyone. Using the same password for company and personal accounts is not a guideline to protect your password, as it increases the risk of compromising your password if one of your accounts is hacked or breached. You should use different and unique passwords for each account, and change them regularly. Sharing passwords with anyone is not a guideline to protect your password, as it reduces the security and accountability of your password. You should keep your password confidential and never disclose it to anyone, even if they claim to be authorized or trustworthy. Don't use the same password for various company system security access is a guideline to protect your password, as it prevents unauthorized access or misuse of your password if one of the systems is compromised or breached.
You should use different and complex passwords for each system, and follow the password policies and standards of the organization. Change a temporary password on first log-on is a guideline to protect your password, as it prevents unauthorized access or misuse of your password if the temporary password is intercepted or leaked. You should change the temporary password to a personal and secure password as soon as possible, and avoid using default or predictable passwords. References: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 43. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 15.


NEW QUESTION # 190
選擇以下選項中的兩個,這些選項由審核團隊中的法律技術專家在認證審核期間負責。

  • A. 為審核團隊提供法律檢查點建議
  • B. 批評組織的法律合規問題
  • C. 評估受審核方的法律知識
  • D. 會見該組織的法定代理人
  • E. 驗證組織的合法地位
  • F. 與受審核方討論複雜的法律問題

Answer: A,E

Explanation:
A legal technical expert (LTE) is a person who provides specific knowledge or expertise related to the legal aspects of the information security management system (ISMS) during a certification audit. The LTE is not an auditor, but a member of the audit team who supports the auditors in collecting and evaluating the audit evidence. The LTE is not responsible for evaluating the auditee's legal knowledge, criticising the organisation' s legal compliance issues, or debating complex legal points with the auditee, as these tasks may be beyond the scope of the audit, or may compromise the objectivity and impartiality of the audit. The LTE is responsible for advising on legal checkpoints for the audit team, such as the applicable legal, regulatory, and contractual requirements, the relevant sources of information, the methods of verification, and the criteria of evaluation.
The LTE is also responsible for verifying the legal status of the organisation, such as the registration, licensing, authorisation, or accreditation of the organisation, and the compliance with the relevant laws and regulations. References:
* What is the role of a technical expert in ISO audit?
* Roles, Responsibilities & Authorities for ISO 27001 5.3
* Guide to Become an ISO 27001 Lead Auditor


NEW QUESTION # 191
情境 8:EsBank 自 9 月起為愛沙尼亞銀行業提供銀行和金融解決方案
2010年,該公司在全國擁有30家分行和100多台ATM機。
EsBank 在高度監管的行業中運營,必須遵守許多有關資料安全和隱私的法律和法規。他們需要透過實施技術和非技術控制來管理整個營運的資訊安全。 EsBank 決定實施基於 ISO/IEC 的 ISMS
27001,因為它提供了更好的安全性、更多的風險控制以及符合法律法規的關鍵要求。
在成功實施 ISMS 九個月後,EsBank 決定由獨立認證機構根據 ISO/IEC 27001 對其 ISMS 進行認證。
第一階段和第二階段審核是共同進行的,發現了一些不符合項。第一個不合格之處與 EsBank 的資訊標籤有關。該公司有資訊分類方案,但沒有資訊標籤程序。因此,需要相同保護等級的文件將被貼上不同的標籤(有時為機密,有時為敏感)。
考慮到所有文件也以電子方式存儲,不合格情況也影響了媒體處理。審計小組透過抽樣得出結論,200 個可移動媒體中有 50 個儲存了被錯誤分類為機密的敏感資訊。根據資訊分類方案,允許將機密資訊儲存在可移動媒體中,而嚴格禁止儲存敏感資訊。這標誌著另一個不合格之處。
他們起草了不合格報告,並與 EsBank 代表討論了審計結論,代表同意在兩個月內針對發現的不合格問題提交行動計劃。
EsBank 接受了審計組組長提出的解決方案。他們根據實體和電子格式的分類方案起草了資訊標籤程序,解決了不合格問題。可移動媒體程式也基於此程式進行了更新。
審計完成兩週後,EsBank 提交了總體行動計畫。在那裡,他們解決了檢測到的不合格問題以及採取的糾正措施,但沒有包括有關受影響的系統、控製或操作的任何詳細資訊。審核小組評估了該行動計劃並得出結論,該計劃將解決不合格問題。然而,EsBank 收到了不利的認證建議。
根據上述場景,回答以下問題:
根據情境8,EsBank 提交了總體行動計畫。這是可以接受的嗎?

  • A. 是的,具有相同根本原因的不符合項應該有一個總體行動計劃
  • B. 不,行動計畫應該只解決一個不合格問題
  • C. 不,一般行動計畫無法修正不合格項

Answer: C


NEW QUESTION # 192
......

Get 100% Authentic PECB ISO-IEC-27001-Lead-Auditor-CN Dumps with Correct Answers: https://www.actualtestsit.com/PECB/ISO-IEC-27001-Lead-Auditor-CN-exam-prep-dumps.html

New Training Course ISO-IEC-27001-Lead-Auditor-CN Tutorial Preparation Guide: https://drive.google.com/open?id=1-drOhPTY-8_FK-MGd8W-uKYWB2qdL2Xa