Question 46

After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; however, their decision was not documented. Is this acceptable?
  • Question 47

    All are prohibited in acceptable use of information assets, except:
  • Question 48

    You are an experienced ISMS audit team leader guiding an auditor in training. Your team has just completed a third-party surveillance audit of a mobile telecom provider. The auditor in training asks you how you intend to prepare for the Closing meeting. Which four of the following are appropriate responses?
  • Question 49

    An auditor of organisation A performs an audit of supplier B.
    Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having identified findings in B's information security management system?
  • Question 50

    You are an audit team leader who has just completed a third-party audit of a mobile telecommunication provider. You are preparing your audit report and are just about to complete a section headed 'confidentiality'.
    An auditor in training on your team asks you if there are any circumstances under which the confidential report can be released to third parties.
    Which four of the following responses are false?