ISO-IEC-27001-LEAD-AUDITOR Web TestEngine demo

Exit VCEDump ISO-IEC-27001-LEAD-AUDITOR PECB Certified ISO/IEC 27001 Lead Auditor exam
Question 23 of 44
0% complete
Q23 Single choice

As the Information Security Management System audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer. During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC
27001:
2022. She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure.

When the auditee was asked why there was a delay in removing access they replied, 'no one was available in the IT department during that period as a result of COVID-19. As soon as an IT officer became available the rights were removed.

You note that she intends to raise a minor non-conformity against Access rights control (5.18).

How should you respond to this?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in