Concepts and Principles
15%of exam
Audit Concepts + Responsibilities
15%of exam
Planning the Audit
15%of exam
Conducting the Audit
35%of exam
Reporting and Closing Out
20%of exam
Quick Facts
- Exam
- PR373 Lead Auditor
- Standard
- ISO/IEC 27001:2022
- Credential
- ISMS Lead Auditor
- Questions
- 40 (online exam)
- Time
- 1h 45m online
- Pass mark
- Not published
- Level
- Professional
- Training
- 40-hour minimum course
- Format
- MCQ + scenarios
- Body
- CQI and IRCA
CIA Triad
Confidentiality + Integrity + Availability
ISMS vs Audit
ISMS
- The managed system
- Owned by organization
- Runs continuously
Audit
- Evaluates the ISMS
- Owned by auditor
- Point-in-time sample
System vs evaluation
Annex A Theme Picker
- Policies, roles, suppliers→Organizational(Theme 5)
- Screening, awareness, NDAs→People(Theme 6)
- Locks, monitoring, equipment→Physical(Theme 7)
- Logging, crypto, backup→Technological(Theme 8)
- Cloud service security→5.23(Organizational)
- Secure coding practices→8.28(Technological)
ISO 27001 Clauses 4-10
- Clause 4
- Context, interested parties, scope
- Clause 5
- Leadership, policy, roles
- Clause 6
- Planning, risk, objectives, changes
- Clause 7
- Support: competence, awareness, docs
- Clause 8
- Operation, risk assessment, treatment
- Clause 9
- Monitoring, internal audit, review
- Clause 10
- Improvement, nonconformity, corrective action
PDCA to Clauses
Plan 4-7, Do 8, Check 9, Act 10
2013 vs 2022 Annex A
2013
- 114 controls
- 14 domains
- A.5 to A.18
2022
- 93 controls
- 4 themes
- 11 new controls
Restructured, not weaker
PDCA + Core Terms
- ISMS
- Risk-based security management system
- CIA Triad
- Confidentiality, integrity, availability
- PDCA
- Plan-Do-Check-Act improvement cycle
- SoA
- Statement of ApplicabilityClause 6
- Risk assessment
- Identify and analyze risks
- Risk treatment
- Select controls for risks
- Documented information
- Records and procedures
- ISO 27000
- ISMS vocabulary and terms
Annex A Themes OPPT
Org 37, People 8, Physical 14, Tech 34
Annex A 2022 Themes
- Total controls
- 93 controls, 4 themes2022
- Organizational (5)
- 37 controls, policies, roles
- People (6)
- 8 controls, HR security
- Physical (7)
- 14 controls, sites, equipment
- Technological (8)
- 34 controls, logical safeguards
- 2013 legacy
- 114 controls, 14 domains
11 New 2022 Controls
- 5.7
- Threat intelligence
- 5.23
- Cloud services security
- 5.30
- ICT continuity readiness
- 7.4
- Physical security monitoring
- 8.9
- Configuration management
- 8.10
- Information deletion
- 8.11
- Data masking
- 8.12
- Data leakage prevention
- 8.16
- Monitoring activities
- 8.23
- Web filtering
- 8.28
- Secure coding
7 Audit Principles
Integrity Fair Care Confidential Independent Evidence Risk
Internal vs Certification Audit
Internal (first-party)
- Self-assessment
- Clause 9.2
- Can use own staff
Certification (third-party)
- Independent body
- Under ISO 17021
- Grants certificate
Internal vs independent
ISO 19011 Audit Principles
- Integrity
- Honesty and professionalism
- Fair presentation
- Report truthfully and accurately
- Due professional care
- Diligence and judgment
- Confidentiality
- Protect audit information
- Independence
- Impartial, no audit bias
- Evidence-based
- Verifiable, sampled evidence
- Risk-based
- Focus on higher risks
Audit Party Types
- First-party
- Internal self-audit
- Second-party
- Customer or supplier audit
- Third-party
- Independent certification audit
- Combined audit
- Two standards together
- Joint audit
- Two bodies, one auditee
Governing Standards
- ISO/IEC 27001
- ISMS requirements, certifiable
- ISO/IEC 27002
- Control implementation guidance
- ISO/IEC 27000
- Overview and vocabulary
- ISO 19011
- Auditing management systems
- ISO/IEC 17021-1
- Certification body requirements
- ISO/IEC 27006
- ISMS certification accreditation
Audit Roles
- Audit team leader
- Leads, decides findings
- Auditor
- Collects and verifies evidence
- Technical expert
- Advises, cannot audit alone
- Auditee
- Organization being audited
- Client
- Requests the audit
- Guide/observer
- Assists, does not audit
Stage 1 vs Stage 2
Stage 1
- Documentation review
- Readiness check
- Plans Stage 2
Stage 2
- Implementation audit
- Effectiveness evidence
- On-site sampling
Readiness vs effectiveness
Stage 1 vs Stage 2
- Review documentation and SoA→Stage 1
- Check Stage 2 readiness→Stage 1
- Confirm internal audit done→Stage 1
- Evaluate implementation→Stage 2
- Sample objective evidence→Stage 2
- Confirm control effectiveness→Stage 2
- Recommend certification→Stage 2
Programme and Plan
- Audit programme
- Set of audits, timeframe
- Audit plan
- Schedule for one audit
- Objectives
- Why the audit runs
- Scope
- Boundaries, sites, processes
- Criteria
- Standard, policy, requirements
- Audit checklist
- Working document, prompts
Certification Cycle
- Stage 1
- Readiness and documentation review
- Stage 2
- Implementation and effectiveness audit
- Surveillance
- Years 1 and 2
- Recertification
- Year 3 renewal audit
- 3-year cycle
- Full certification period
- Special audit
- Scope change or complaint
Evidence and Sampling
- Objective evidence
- Verifiable records or facts
- Audit trail
- Trace evidence end-to-end
- Sampling
- Representative subset checked
- Trace forward
- Input to output
- Trace backward
- Output back to input
- Corroboration
- Confirm from multiple sources
Evidence Techniques
- Interview
- Open-ended questioning
- Observation
- Watch process performed
- Document review
- Policies, procedures, plans
- Record review
- Logs, results, evidence
- Walkthrough
- Follow process live
- Re-performance
- Auditor repeats control
NC Statement Parts
Requirement + Evidence + Deficiency = valid NC
Major vs Minor NC
Major NC
- Systemic failure
- Absent ISMS element
- Blocks certification
Minor NC
- Isolated lapse
- System still works
- Correct and continue
Systemic vs isolated
Major vs Minor NC
- ISMS element absent→Major NC(Total breakdown)
- Systemic repeated failure→Major NC
- Many minors, one clause→Major NC(Upgrade)
- Risk untreated, no justification→Major NC
- Isolated single lapse→Minor NC
- One sample record missing→Minor NC
- Met but improvable→OFI(Not a NC)
Findings and Nonconformity
- Conformity
- Requirement is met
- Nonconformity
- Requirement not met
- Major NC
- Systemic or total failure
- Minor NC
- Isolated single lapse
- OFI
- Opportunity for improvement
- NC statement
- Requirement, evidence, deficiency
Correction vs Corrective Action
Correction
- Fix the symptom
- Immediate containment
- No cause analysis
Corrective action
- Remove root cause
- Prevent recurrence
- Needs verification
Symptom vs cause
CAPA and Follow-Up
- Correction
- Fix the immediate problem
- Corrective action
- Remove the root cause
- Root cause
- Underlying reason for NC
- Containment
- Limit immediate impact
- Verification
- Confirm action effective
- Follow-up audit
- Check corrective action closed
Nonconformity vs OFI
Nonconformity
- Requirement not met
- Must be corrected
- Needs evidence
OFI
- Requirement met
- Suggestion only
- Optional to act
Mandatory vs optional
Common Traps
Annex A not a checklist
Selected via risk treatment ≠ SoA justifies inclusion/exclusion
Incident is not major NC
Incident alone is not NC ≠ Failure to respond is
Correction vs corrective action
Correction fixes symptom ≠ Corrective action removes cause
OFI is not nonconformity
OFI is optional ≠ NC must be corrected
Stage 1 is not Stage 2
Stage 1 checks readiness ≠ Stage 2 checks effectiveness
SoA vs risk treatment plan
SoA lists control decisions ≠ RTP plans implementation actions
93 controls not mandatory
Annex A is informative ≠ Applicability set by risk
Last Minute
- 1.Annex A 2022 = 93 controls
- 2.Org 37, People 8 controls
- 3.Physical 14, Tech 34 controls
- 4.11 new controls in 2022
- 5.Clauses 4-10 are auditable
- 6.SoA links risk to controls
- 7.ISO 19011 = 7 principles
- 8.Major NC = systemic failure
- 9.Minor NC = isolated lapse
- 10.Correction fixes; corrective removes cause
- 11.Stage 1 readiness; Stage 2 effectiveness
- 12.NC = requirement + evidence + gap
- 13.Third-party audit uses ISO 17021
- 14.OFI is optional, not NC
Explore More CQI and IRCA Auditor Training Exams
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
