Exam ISO-IEC-27001-Lead-Auditor Topic 1 Question 12 Discussion
Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 12
Topic #: 1
Question #: 12
Topic #: 1
Scenario 9
CloudFort, a small networking company, provides network security, cloud computing, and virtualization solutions. The company has recently been certified in an information security management system (ISMS) based on the ISO/IEC 27001 standard, which has resulted in a spike in its recognition, confirming the maturity of CloudFort's operation.
CloudFort continually reviewed and enhanced its security controls and the overall effectiveness and efficiency of the ISMS by conducting internal audits. Due to its size and desire for greater objectivity, the top management decided to outsource the internal audit function to ensure the internal audit is independent of the audited activities and holds an advisory role in the continual improvement of the ISMS.
After the initial certification audit, the company created a new department specializing in data storage solutions. It offered routers and switches optimized for data centers and software-based networking devices, such as network virtualization and network security appliances. Because of the new department, CloudFort initiated a risk assessment process and an internal audit. Following the internal audit results, the company confirmed the effectiveness and efficiency of the new processes and controls.
After determining that the new department fully complies with ISO/IEC 27001 requirements, top management decided to include it in the certification scope. They submitted a request to the certification body for an extension of the certification scope to ensure that the department's processes and security measures fully align with the overall ISMS.
One year after the initial certification audit, the certification body conducted another audit of CloudFort's ISMS. This audit aimed to determine CloudFort's ISMS fulfillment of specified ISO/IEC 27001 requirements and ensure that the ISMS is being continually improved. The audit team confirmed that the certified ISMS fulfills the standard requirements. Nonetheless, the new department introduced changes that significantly affected how the overall management system was governed, requiring updates to existing processes and controls.
Moreover, although CloudFort requested an extension of the certification scope, they failed to provide timely updates on the impact of the new department on the ISMS to the certification body. Thus, CloudFort's certification was suspended.
Question
CloudFort requested an extension of the certification scope to include the new department. How would you classify this situation? Refer to Scenario 9.
CloudFort, a small networking company, provides network security, cloud computing, and virtualization solutions. The company has recently been certified in an information security management system (ISMS) based on the ISO/IEC 27001 standard, which has resulted in a spike in its recognition, confirming the maturity of CloudFort's operation.
CloudFort continually reviewed and enhanced its security controls and the overall effectiveness and efficiency of the ISMS by conducting internal audits. Due to its size and desire for greater objectivity, the top management decided to outsource the internal audit function to ensure the internal audit is independent of the audited activities and holds an advisory role in the continual improvement of the ISMS.
After the initial certification audit, the company created a new department specializing in data storage solutions. It offered routers and switches optimized for data centers and software-based networking devices, such as network virtualization and network security appliances. Because of the new department, CloudFort initiated a risk assessment process and an internal audit. Following the internal audit results, the company confirmed the effectiveness and efficiency of the new processes and controls.
After determining that the new department fully complies with ISO/IEC 27001 requirements, top management decided to include it in the certification scope. They submitted a request to the certification body for an extension of the certification scope to ensure that the department's processes and security measures fully align with the overall ISMS.
One year after the initial certification audit, the certification body conducted another audit of CloudFort's ISMS. This audit aimed to determine CloudFort's ISMS fulfillment of specified ISO/IEC 27001 requirements and ensure that the ISMS is being continually improved. The audit team confirmed that the certified ISMS fulfills the standard requirements. Nonetheless, the new department introduced changes that significantly affected how the overall management system was governed, requiring updates to existing processes and controls.
Moreover, although CloudFort requested an extension of the certification scope, they failed to provide timely updates on the impact of the new department on the ISMS to the certification body. Thus, CloudFort's certification was suspended.
Question
CloudFort requested an extension of the certification scope to include the new department. How would you classify this situation? Refer to Scenario 9.
Suggested Answer: B Vote an answer
This situation is acceptable, making option B the correct answer. ISO/IEC 17021-1 and ISO/IEC 27006 explicitly allow certified organizations to request an extension of the certification scope after initial certification. It is common and fully permissible for organizations to begin with a limited or reduced scope and later expand it as the ISMS matures, business operations grow, or new departments are created.
ISO/IEC 27001 does not require the full organization to be included in the initial certification scope. Instead, it requires the scope to be clearly defined, documented, and controlled. When CloudFort created a new department, it correctly initiated a risk assessment and internal audit, and then formally requested a scope extension from the certification body. This demonstrates alignment with ISO requirements and good ISMS governance.
Option A is incorrect because scope extensions do not require a full recertification audit unless the certification body determines that the changes are so extensive that they fundamentally alter the ISMS. Option C is also incorrect because expanding the scope does not automatically require a complete re-audit of the entire organization; the certification body typically performs a focused extension audit covering the new scope elements and their interaction with the existing ISMS.
The suspension in Scenario 9 occurred not because the scope extension request was unacceptable, but because CloudFort failed to provide timely and sufficient information to the certification body regarding the impact of the new department. The act of requesting a scope extension itself was appropriate and acceptable.
ISO/IEC 27001 does not require the full organization to be included in the initial certification scope. Instead, it requires the scope to be clearly defined, documented, and controlled. When CloudFort created a new department, it correctly initiated a risk assessment and internal audit, and then formally requested a scope extension from the certification body. This demonstrates alignment with ISO requirements and good ISMS governance.
Option A is incorrect because scope extensions do not require a full recertification audit unless the certification body determines that the changes are so extensive that they fundamentally alter the ISMS. Option C is also incorrect because expanding the scope does not automatically require a complete re-audit of the entire organization; the certification body typically performs a focused extension audit covering the new scope elements and their interaction with the existing ISMS.
The suspension in Scenario 9 occurred not because the scope extension request was unacceptable, but because CloudFort failed to provide timely and sufficient information to the certification body regarding the impact of the new department. The act of requesting a scope extension itself was appropriate and acceptable.
by Teresa at Aug 27, 2026, 11:06 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).