An internal auditor wants to map ISMS improvement sources correctly. Which pairing of source and resulting management-system artifact is correctly matched?
- A.A confirmed audit finding of an unmet requirement maps to a nonconformity
- B.A successful penetration test with no findings maps to a major nonconformity
- C.Routine completion of a scheduled task maps to a corrective action
- D.A vendor newsletter maps to a mandatory ISMS change
Why A is correct
An audit finding that a requirement is not met is, by definition, a nonconformity. A clean penetration test produces no nonconformity, and routine task completion or a newsletter do not by themselves create corrective actions.
Know someone studying for ISO 27001? Send them this one.