Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company has had an
operational information security management system (ISMS) based on ISO/IEC 27001 requirements and a
quality management system (QMS) based on ISO 9001 for approximately two years. Recently, it has appliedfor a j^ombined certification audit in order to obtain certification against ISO/IEC 27001 and ISO 9001.
After selecting the certification body, NetworkFuse prepared the employees for the audit The company
decided to not conduct a self-evaluation before the audit since, according to the top management, it was not
necessary. In addition, it ensured the availability of documented information, including internal audit reports
and management reviews, technologies in place, and the general operations of the ISMS and the QMS.
However, the company requested from the certification body that the documentation could not be carried
off-site
However, the audit was not performed within the scheduled days because NetworkFuse rejected the audit team
leader assigned and requested their replacement The company asserted that the same audit team leader issued a
recommendation for certification to its main competitor, which, for the company's top management, was a
potential conflict of interest. The request was not accepted by the certification body
Based on the scenario above, answer the following question:
Does NetworkFuse fulfill the prerequisites for a certification audit?
What supports the continual improvement of an ISMS?
Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company has had an
operational information security management system (ISMS) based on ISO/IEC 27001 requirements and a
quality management system (QMS) based on ISO 9001 for approximately two years. Recently, it has applied
for a j^ombined certification audit in order to obtain certification against ISO/IEC 27001 and ISO 9001.
After selecting the certification body, NetworkFuse prepared the employees for the audit The company
decided to not conduct a self-evaluation before the audit since, according to the top management, it was not
necessary. In addition, it ensured the availability of documented information, including internal audit reports
and management reviews, technologies in place, and the general operations of the ISMS and the QMS.
However, the company requested from the certification body that the documentation could not be carried
off-site
However, the audit was not performed within the scheduled days because NetworkFuse rejected the audit team
leader assigned and requested their replacement The company asserted that the same audit team leader issued a
recommendation for certification to its main competitor, which, for the company's top management, was a
potential conflict of interest. The request was not accepted by the certification body
The certification body rejected NetworkFuse's request to change the audit team leader. Is this acceptable?
Refer to scenario 10.
Scenario 2: Beauty is a cosmetics company that haDue to this transformation of the business model, a number of security controls were implemented based on
the identified threats and vulnerabilities associated to critical assets. To protect customers' information.
Beauty's employees had to sign a confidentiality agreement. In addition, the company reviewed all user access
rights so that only authorized personnel can have access to sensitive files and drafted a new segregation of
duties chart.
However, the transition was difficult for the IT team, who had to deal with a security incident not long after
transitioning to the e commerce model. After investigating the incident, the team concluded that due to the
out-of-date anti-malware software, an attacker gamed access to their files and exposed customers' information,
including their names and home addresses.
The IT team decided to stop using the old anti-malware software and install a new one which would
automatically remove malicious code in case of similar incidents. The new software was installed in every
workstation within the company. After installing the new software, the team updated it with the latest malware
definitions and enabled the automatic update feature to keep it up to date at all times. Additionally, they
established an authentication process that requires a user identification and password when accessing sensitive
information.
In addition, Beauty conducted a number of information security awareness sessions for the IT team and other
employees that have access to confidential information in order to raise awareness on the importance of
system and network security.
According to scenario 2. Beauty has reviewed all user access rights. What type of control is this?
ent process to an external provider operating online payments systems that support online money
transfers.
Scenario 8: SunDee is an American biopharmaceutical company, headquartered in California, the US. It
specializes in developing novel human therapeutics, with a focus on cardiovascular diseases, oncology, bone
health, and inflammation. The company has had an information security management system (ISMS) based on
SO/IEC 27001 in place for the past two years. However, it has not monitored or measured the performance
and effectiveness of its ISMS and conducted management reviews regularly
Just before the recertification audit, the company decided to conduct an internal audit. It also asked most of
their staff to compile the written individual reports of the past two years for their departments. This left the
Production Department with less than the optimum workforce, which decreased the company's stock.
Tessa was SunDee's internal auditor. With multiple reports written by 50 different employees, the internal
audit process took much longer than planned, was very inconsistent, and had no qualitative measures
whatsoever Tessa concluded that SunDee must evaluate the performance of the ISMS adequately. She defined
SunDee's negligence of ISMS performance evaluation as a major nonconformity, so she wrote a
nonconformity report including the description of the nonconformity, the audit findings, and
recommendations. Additionally, Tessa created a new plan which would enable SunDee to resolve these issues
and presented it to the top management
According to scenario 8, Tessa created a plan for ISMS monitoring and measurement and presented it to the
top management Is this acceptable?
© Copyrights FreePDFQuestions 2026. All Rights Reserved
We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.