Cheat sheet

CQI/IRCA ISMS Lead Auditor Cheat Sheet

Concepts and Principles

15%of exam

Clauses 4-10PDCA CycleAnnex A ThemesNew 2022 ControlsCIA TriadStatement of Applicability

Audit Concepts + Responsibilities

15%of exam

Planning the Audit

15%of exam

Audit ProgrammeAudit PlanCertification CycleStage 1 vs Stage 2Risk-Based Audit

Conducting the Audit

35%of exam

Objective EvidenceEvidence TechniquesSamplingAudit TrailOpening Meeting

Reporting and Closing Out

20%of exam

NonconformitiesMajor vs MinorCAPA + Follow-UpClosing MeetingAudit Report

Quick Facts

Exam
PR373 Lead Auditor
Standard
ISO/IEC 27001:2022
Credential
ISMS Lead Auditor
Questions
40 (online exam)
Time
1h 45m online
Pass mark
Not published
Level
Professional
Training
40-hour minimum course
Format
MCQ + scenarios
Body
CQI and IRCA

CIA Triad

Confidentiality + Integrity + Availability

C: keep secretI: keep accurateA: keep available

ISMS vs Audit

ISMS

  • The managed system
  • Owned by organization
  • Runs continuously

Audit

  • Evaluates the ISMS
  • Owned by auditor
  • Point-in-time sample

System vs evaluation

Annex A Theme Picker

  1. Policies, roles, suppliersOrganizational(Theme 5)
  2. Screening, awareness, NDAsPeople(Theme 6)
  3. Locks, monitoring, equipmentPhysical(Theme 7)
  4. Logging, crypto, backupTechnological(Theme 8)
  5. Cloud service security5.23(Organizational)
  6. Secure coding practices8.28(Technological)

ISO 27001 Clauses 4-10

Clause 4
Context, interested parties, scope
Clause 5
Leadership, policy, roles
Clause 6
Planning, risk, objectives, changes
Clause 7
Support: competence, awareness, docs
Clause 8
Operation, risk assessment, treatment
Clause 9
Monitoring, internal audit, review
Clause 10
Improvement, nonconformity, corrective action

PDCA to Clauses

Plan 4-7, Do 8, Check 9, Act 10

Plan: clauses 4-7Do: clause 8Check: clause 9Act: clause 10

2013 vs 2022 Annex A

2013

  • 114 controls
  • 14 domains
  • A.5 to A.18

2022

  • 93 controls
  • 4 themes
  • 11 new controls

Restructured, not weaker

PDCA + Core Terms

ISMS
Risk-based security management system
CIA Triad
Confidentiality, integrity, availability
PDCA
Plan-Do-Check-Act improvement cycle
SoA
Statement of ApplicabilityClause 6
Risk assessment
Identify and analyze risks
Risk treatment
Select controls for risks
Documented information
Records and procedures
ISO 27000
ISMS vocabulary and terms

Annex A Themes OPPT

Org 37, People 8, Physical 14, Tech 34

O: 37 organizationalP: 8 peopleP: 14 physicalT: 34 technological

Annex A 2022 Themes

Total controls
93 controls, 4 themes2022
Organizational (5)
37 controls, policies, roles
People (6)
8 controls, HR security
Physical (7)
14 controls, sites, equipment
Technological (8)
34 controls, logical safeguards
2013 legacy
114 controls, 14 domains

11 New 2022 Controls

5.7
Threat intelligence
5.23
Cloud services security
5.30
ICT continuity readiness
7.4
Physical security monitoring
8.9
Configuration management
8.10
Information deletion
8.11
Data masking
8.12
Data leakage prevention
8.16
Monitoring activities
8.23
Web filtering
8.28
Secure coding

7 Audit Principles

Integrity Fair Care Confidential Independent Evidence Risk

IntegrityFair presentationDue careConfidentialityIndependenceEvidence-basedRisk-based

Internal vs Certification Audit

Internal (first-party)

  • Self-assessment
  • Clause 9.2
  • Can use own staff

Certification (third-party)

  • Independent body
  • Under ISO 17021
  • Grants certificate

Internal vs independent

ISO 19011 Audit Principles

Integrity
Honesty and professionalism
Fair presentation
Report truthfully and accurately
Due professional care
Diligence and judgment
Confidentiality
Protect audit information
Independence
Impartial, no audit bias
Evidence-based
Verifiable, sampled evidence
Risk-based
Focus on higher risks

Audit Party Types

First-party
Internal self-audit
Second-party
Customer or supplier audit
Third-party
Independent certification audit
Combined audit
Two standards together
Joint audit
Two bodies, one auditee

Governing Standards

ISO/IEC 27001
ISMS requirements, certifiable
ISO/IEC 27002
Control implementation guidance
ISO/IEC 27000
Overview and vocabulary
ISO 19011
Auditing management systems
ISO/IEC 17021-1
Certification body requirements
ISO/IEC 27006
ISMS certification accreditation

Audit Roles

Audit team leader
Leads, decides findings
Auditor
Collects and verifies evidence
Technical expert
Advises, cannot audit alone
Auditee
Organization being audited
Client
Requests the audit
Guide/observer
Assists, does not audit

Stage 1 vs Stage 2

Stage 1

  • Documentation review
  • Readiness check
  • Plans Stage 2

Stage 2

  • Implementation audit
  • Effectiveness evidence
  • On-site sampling

Readiness vs effectiveness

Stage 1 vs Stage 2

  1. Review documentation and SoAStage 1
  2. Check Stage 2 readinessStage 1
  3. Confirm internal audit doneStage 1
  4. Evaluate implementationStage 2
  5. Sample objective evidenceStage 2
  6. Confirm control effectivenessStage 2
  7. Recommend certificationStage 2

Programme and Plan

Audit programme
Set of audits, timeframe
Audit plan
Schedule for one audit
Objectives
Why the audit runs
Scope
Boundaries, sites, processes
Criteria
Standard, policy, requirements
Audit checklist
Working document, prompts

Certification Cycle

Stage 1
Readiness and documentation review
Stage 2
Implementation and effectiveness audit
Surveillance
Years 1 and 2
Recertification
Year 3 renewal audit
3-year cycle
Full certification period
Special audit
Scope change or complaint

Evidence and Sampling

Objective evidence
Verifiable records or facts
Audit trail
Trace evidence end-to-end
Sampling
Representative subset checked
Trace forward
Input to output
Trace backward
Output back to input
Corroboration
Confirm from multiple sources

Evidence Techniques

Interview
Open-ended questioning
Observation
Watch process performed
Document review
Policies, procedures, plans
Record review
Logs, results, evidence
Walkthrough
Follow process live
Re-performance
Auditor repeats control

NC Statement Parts

Requirement + Evidence + Deficiency = valid NC

Requirement: the criteriaEvidence: objective proofDeficiency: the gap

Major vs Minor NC

Major NC

  • Systemic failure
  • Absent ISMS element
  • Blocks certification

Minor NC

  • Isolated lapse
  • System still works
  • Correct and continue

Systemic vs isolated

Major vs Minor NC

  1. ISMS element absentMajor NC(Total breakdown)
  2. Systemic repeated failureMajor NC
  3. Many minors, one clauseMajor NC(Upgrade)
  4. Risk untreated, no justificationMajor NC
  5. Isolated single lapseMinor NC
  6. One sample record missingMinor NC
  7. Met but improvableOFI(Not a NC)

Findings and Nonconformity

Conformity
Requirement is met
Nonconformity
Requirement not met
Major NC
Systemic or total failure
Minor NC
Isolated single lapse
OFI
Opportunity for improvement
NC statement
Requirement, evidence, deficiency

Correction vs Corrective Action

Correction

  • Fix the symptom
  • Immediate containment
  • No cause analysis

Corrective action

  • Remove root cause
  • Prevent recurrence
  • Needs verification

Symptom vs cause

CAPA and Follow-Up

Correction
Fix the immediate problem
Corrective action
Remove the root cause
Root cause
Underlying reason for NC
Containment
Limit immediate impact
Verification
Confirm action effective
Follow-up audit
Check corrective action closed

Nonconformity vs OFI

Nonconformity

  • Requirement not met
  • Must be corrected
  • Needs evidence

OFI

  • Requirement met
  • Suggestion only
  • Optional to act

Mandatory vs optional

Common Traps

Annex A not a checklist

Selected via risk treatment SoA justifies inclusion/exclusion

Incident is not major NC

Incident alone is not NC Failure to respond is

Correction vs corrective action

Correction fixes symptom Corrective action removes cause

OFI is not nonconformity

OFI is optional NC must be corrected

Stage 1 is not Stage 2

Stage 1 checks readiness Stage 2 checks effectiveness

SoA vs risk treatment plan

SoA lists control decisions RTP plans implementation actions

93 controls not mandatory

Annex A is informative Applicability set by risk

Last Minute

  1. 1.Annex A 2022 = 93 controls
  2. 2.Org 37, People 8 controls
  3. 3.Physical 14, Tech 34 controls
  4. 4.11 new controls in 2022
  5. 5.Clauses 4-10 are auditable
  6. 6.SoA links risk to controls
  7. 7.ISO 19011 = 7 principles
  8. 8.Major NC = systemic failure
  9. 9.Minor NC = isolated lapse
  10. 10.Correction fixes; corrective removes cause
  11. 11.Stage 1 readiness; Stage 2 effectiveness
  12. 12.NC = requirement + evidence + gap
  13. 13.Third-party audit uses ISO 17021
  14. 14.OFI is optional, not NC
Same family resources

Explore More CQI and IRCA Auditor Training Exams

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.