Free CQI/IRCA ISMS Lead Auditor Exam Flashcards
Memorize 50 essential terms and definitions for the CQI/IRCA Certified ISO/IEC 27001:2022 Lead Auditor (ISMS) Course Exam (PR373). See the term, recall the definition, then flip to check yourself.
ISO/IEC 27001:2022 Clause 4 — Context of the Organization
Requires identifying internal and external issues relevant to the ISMS, the needs and expectations of interested parties, and defining the ISMS scope. Auditors confirm the scope is documented and justified. Clause 4 is where the ISMS boundaries are set.
Filter by Topic
Jump to Card
About These CQI/IRCA ISMS Lead Auditor Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the CQI/IRCA Certified ISO/IEC 27001:2022 Lead Auditor (ISMS) Course Exam (PR373). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
ISO/IEC 27001:2022 Clause 4 — Context of the Organization
Requires identifying internal and external issues relevant to the ISMS, the needs and expectations of interested parties, and defining the ISMS scope. Auditors confirm the scope is documented and justified. Clause 4 is where the ISMS boundaries are set.
ISO/IEC 27001:2022 Clause 5 — Leadership
Top management must demonstrate commitment, establish an information security policy aligned to the organization's direction, and assign roles, responsibilities and authorities. Auditors seek evidence that leadership actively drives the ISMS rather than delegating it entirely.
ISO/IEC 27001:2022 Clause 6 — Planning
Covers information security risk assessment, risk treatment, and information security objectives. It requires the risk treatment process and the Statement of Applicability (SoA). This is the 'Plan' engine of the ISMS.
ISO/IEC 27001:2022 Clause 7 — Support
Requires resources, competence, awareness, communication, and documented information to operate the ISMS. Auditors check that people are competent and aware, and that documented information is controlled (created, updated, and protected).
ISO/IEC 27001:2022 Clause 8 — Operation
Requires the organization to plan, implement and control the processes needed to meet ISMS requirements, and to actually carry out the information security risk assessment and risk treatment. This is the 'Do' phase, turning Clause 6 plans into practice.
ISO/IEC 27001:2022 Clause 9 — Performance Evaluation
Requires monitoring, measurement, analysis and evaluation, plus internal audit and management review. This is the 'Check' phase. Internal audit and management review are among the first things a certification auditor looks for as evidence the ISMS is self-correcting.
ISO/IEC 27001:2022 Clause 10 — Improvement
Covers continual improvement and nonconformity & corrective action. This is the 'Act' phase. Note: in the 2022 version the sub-clause order was reversed, so continual improvement (10.1) now precedes nonconformity and corrective action (10.2).
Which ISO/IEC 27001 clauses contain auditable requirements?
Clauses 4-10 hold the mandatory 'shall' requirements an auditor certifies against. Clauses 0-3 (introduction, scope, normative references, terms and definitions) provide context and are not auditable requirements.
How do the ISO/IEC 27001 clauses map to the PDCA cycle?
Plan = Clauses 4-7 (context, leadership, planning, support); Do = Clause 8 (operation); Check = Clause 9 (performance evaluation); Act = Clause 10 (improvement). The standard is structured around the Plan-Do-Check-Act continual-improvement model.
ISO/IEC 27001:2022 Annex A — structure and total controls
Annex A lists 93 reference controls grouped into 4 themes: Organizational (37), People (8), Physical (14) and Technological (34). The 2022 revision consolidated the previous 114 controls and 14 domains into these four themes.
Annex A — Organizational controls (A.5)
37 controls, the largest theme. Covers policies, roles and responsibilities, segregation of duties, supplier and cloud relationships, threat intelligence, incident management, and business continuity. Example new 2022 control: threat intelligence.
Annex A — People controls (A.6)
8 controls, the smallest theme. Covers screening, terms and conditions of employment, awareness and training, the disciplinary process, responsibilities after termination or change, confidentiality agreements, and remote working.
Annex A — Physical controls (A.7)
14 controls. Covers physical security perimeters, entry controls, protection against physical and environmental threats, equipment siting and maintenance, secure disposal, clear desk/clear screen, and the new control physical security monitoring.
Annex A — Technological controls (A.8)
34 controls, the second-largest theme. Covers access control, cryptography, secure development, logging and monitoring, malware protection, backup, and network security. Includes new 2022 controls such as data masking and secure coding.
How many new controls did ISO/IEC 27001:2022 add, and what are examples?
11 new controls. Examples: threat intelligence; information security for use of cloud services; ICT readiness for business continuity; physical security monitoring; configuration management; information deletion; data masking; data leakage prevention; web filtering; and secure coding.
The CIA triad
The three core objectives of information security: Confidentiality (information not disclosed to unauthorized parties), Integrity (accuracy and completeness of information), and Availability (information accessible when authorized users need it).
ISMS (Information Security Management System)
A systematic, risk-based set of policies, processes and controls to manage information security, defined by ISO/IEC 27001. It preserves the confidentiality, integrity and availability of information through a documented, continually improving management system.
Risk assessment vs. risk treatment (Clause 6.1)
Risk assessment identifies, analyzes and evaluates information security risks. Risk treatment then selects options, modify, retain, avoid or share, and chooses the necessary controls to bring risk to an acceptable level. Assessment always precedes treatment.
Statement of Applicability (SoA)
A mandatory ISMS document (Clause 6.1.3 d) listing the necessary controls, the justification for their inclusion, whether they are implemented, and the justification for excluding any Annex A controls. It links risk treatment to the controls actually applied.
ISO/IEC 27000 vs. 27001 vs. 27002
ISO/IEC 27000 provides the vocabulary and overview; ISO/IEC 27001 defines the certifiable ISMS requirements (Clauses 4-10 plus Annex A); ISO/IEC 27002 gives implementation guidance for the Annex A controls but is not itself certifiable.
ISO/IEC 17021-1 — role in certification audits
Specifies requirements for bodies that audit and certify management systems. It defines the third-party certification process, Stage 1, Stage 2, surveillance and recertification, and requires impartiality between the audit team and the certification decision.
Documented information (ISO/IEC 27001:2022)
The 2022 term that replaced 'documents and records.' It covers information the organization must maintain (such as policies and the SoA) and information retained as evidence of results (records). It must be controlled for availability, protection and version.
ISO 19011:2018 — the seven principles of auditing
1) Integrity, 2) Fair presentation, 3) Due professional care, 4) Confidentiality, 5) Independence, 6) Evidence-based approach, 7) Risk-based approach. Applying them lets auditors working independently reach similar, reliable conclusions.
Which audit principle was added in ISO 19011:2018?
The risk-based approach. It requires auditors to consider risks and opportunities throughout audit planning, conduct, reporting and follow-up, focusing audit effort where it matters most. The 2011 version had only six principles.
First-party, second-party and third-party audits
First-party = internal audit (the organization audits its own ISMS). Second-party = audit by an interested party, such as a customer auditing a supplier. Third-party = independent external audit by a certification body, leading to certification.
Objective evidence (audit)
Records, statements of fact or other verifiable information related to the audit criteria. It can be qualitative or quantitative and is obtained through observation, interview, measurement, or document and record review. Findings must rest on objective, verifiable evidence.
Audit criteria vs. audit evidence vs. audit findings
Audit criteria = the requirements used as a reference (e.g., ISO/IEC 27001, policies, the SoA). Audit evidence = the verifiable information gathered. Audit findings = the result of evaluating that evidence against the criteria, i.e., conformity or nonconformity.
Confidentiality and integrity as auditor conduct (ISO 19011)
Auditors must protect the information they obtain and use it only for audit purposes (confidentiality and security of information), and act honestly, responsibly and within the law (integrity). Breaching confidentiality destroys trust and audit credibility.
Auditor independence and impartiality
Auditors should be independent of the activity being audited and free from bias and conflict of interest so conclusions stay objective. Where full independence is hard (e.g., a small internal audit team), auditors must at least not audit their own work.
Audit programme (ISO 19011)
The arrangements for a set of one or more audits planned for a specific time frame and directed toward a specific purpose. Managing the programme includes setting objectives, determining risks, resourcing, and monitoring and improving the programme over time.
Stage 1 audit (initial certification)
A readiness and documentation review. The auditor confirms the ISMS scope, information security policy, risk assessment and treatment, the SoA, and that internal audits and management review are established. It determines readiness for Stage 2 and helps plan it.
Stage 2 audit (initial certification)
The implementation audit. The auditor gathers objective evidence that the ISMS is implemented, operational and effective against ISO/IEC 27001 and the organization's own requirements. A successful Stage 2 leads to a recommendation for certification.
Audit objectives, scope and criteria
Objectives = what the audit is to achieve (why). Scope = the extent and boundaries, i.e., sites, units, processes and time period (what and where). Criteria = the reference requirements evidence is compared against (against what). All three are defined before the audit.
Audit plan
The description of the activities and arrangements for an individual audit: objectives, scope, criteria, dates and locations, timetable, audit-team roles, and the areas and processes to be audited. It is prepared by the audit team leader and agreed with the auditee.
Why do auditors use sampling?
It is usually impractical to examine every record or activity, so auditors examine a representative sample to reach conclusions efficiently. Sampling introduces uncertainty (sampling risk), so samples must be chosen carefully and conclusions reflect that limitation.
Opening meeting — purpose
Held at the start of the on-site audit to confirm the audit plan, scope, criteria, timetable and methods with the auditee, introduce the audit team, confirm communication channels and confidentiality, and give the auditee the chance to ask questions.
Methods of collecting objective evidence
Interviewing people, observing activities and conditions, and reviewing documents and records (including data). Auditors corroborate information from more than one source where possible before treating it as evidence for a finding.
Audit trail
A path the auditor follows through records and evidence to verify a process operates as intended, for example tracing an access request from approval to provisioning to periodic review. Following trails turns individual records into evidence of a working control.
Why must audit evidence be verifiable?
Only verifiable information can support a defensible finding; unverifiable claims are not evidence. If information cannot be confirmed, the auditor gathers more evidence or records it as unverified. This underpins the evidence-based principle and consistent conclusions.
Nonconformity (audit)
The non-fulfilment of a requirement, a gap between what is required (by ISO/IEC 27001, the organization's own rules, or the SoA) and objective evidence of what is actually done. Nonconformities are graded by significance as major or minor.
Major nonconformity
A significant failure: the absence or total breakdown of a required part of the ISMS, or a situation that raises significant doubt about the ISMS's ability to achieve its intended results. Major nonconformities usually must be resolved before certification is granted.
Minor nonconformity
An isolated lapse or single failure that does not represent a systemic breakdown and does not raise significant doubt about the ISMS overall. It still requires correction and corrective action, but typically does not on its own block certification.
What must a well-written nonconformity statement contain?
Three elements: the requirement not met (the audit criterion), the objective evidence observed, and a clear statement of how that evidence fails to meet the requirement. It must be factual and traceable so the auditee can locate and fix the issue.
Opportunity for improvement (OFI) vs. nonconformity
A nonconformity is a breach of a requirement and must be corrected. An OFI (or observation) is not a breach; it is a suggestion where the ISMS could be strengthened. Auditors must not disguise nonconformities as OFIs, or vice versa.
Closing meeting — purpose
Held at the end of the on-site audit to present the audit findings and conclusions, confirm nonconformities and their grading with the auditee, explain next steps (corrective action and follow-up), and ensure the auditee understands the results before the report is issued.
Audit report — contents
A complete, accurate and clear record of the audit: objectives, scope, criteria, audit team and auditee, dates, findings (conformities and nonconformities), and the audit conclusions. It is the formal deliverable the auditee acts upon and is retained as evidence.
Correction vs. corrective action
Correction is immediate action to fix the detected nonconformity (address the symptom, e.g., re-enable a disabled log). Corrective action eliminates the root cause so the nonconformity does not recur. A sound response includes both, plus root cause analysis.
Root cause analysis and CAPA
Before corrective action, the organization investigates why the nonconformity happened (root cause), not just what happened. CAPA (corrective and preventive action) then addresses that cause. Auditors evaluate whether the true root cause was identified and addressed.
Follow-up and verification of effectiveness
After corrective actions are taken, the auditor verifies they were implemented and were effective in removing the root cause, not just that a plan was written. Verification may be by document review or a follow-up audit, depending on the nonconformity's significance.
Who decides certification, the auditor or the certification body?
The audit team gathers evidence and makes a recommendation, but under ISO/IEC 17021-1 the certification decision is made independently by the certification body, separate from the people who performed the audit. This impartiality stops auditors certifying their own findings.
Frequently Asked Questions
What is the CQI/IRCA ISMS Lead Auditor exam?
It is the assessment attached to the CQI/IRCA Certified ISO/IEC 27001:2022 Lead Auditor (ISMS) course, course code PR373, a 40-hour minimum certified training course. The current online Lead Auditor exam is remotely proctored through SARAS and, per the CQI/IRCA online exams learner guide, consists of 40 questions over 1 hour 45 minutes covering management-system concepts, auditor responsibilities, audit planning, audit conduct, and reporting/close-out.
What topics do these flashcards cover?
All 50 cards map to the ISO/IEC 27001:2022 ISMS Lead Auditor syllabus: Clauses 4-10 (context, leadership, planning and risk, support, operation, performance evaluation, improvement), the 93 Annex A controls across four themes, key definitions (CIA triad, ISMS, Statement of Applicability, PDCA), the ISO 19011:2018 audit principles, and the audit process from planning through conducting, reporting and follow-up.
Does CQI/IRCA publish a passing score or pass rate?
No. No public CQI/IRCA source publishes a specific passing score or pass rate for the ISMS Lead Auditor online exam, so this set marks both as 'Not published by CQI/IRCA' rather than inventing a number. The exam is computer-marked, and results are issued by CQI/IRCA through the training provider.
What happens if I fail the CQI/IRCA ISMS Lead Auditor exam?
CQI/IRCA allows one resit after a failed online exam. The resit must be requested by your Approved Training Partner within 12 months of the first attempt's result-issue date. CQI/IRCA does not publish a fixed mandatory waiting period in days, and only a single resit is permitted, so there is no separate 'after three failures' rule.
How many controls are in ISO/IEC 27001:2022 Annex A?
93 controls in four themes: Organizational (37), People (8), Physical (14) and Technological (34). The 2022 revision reorganized the previous 114 controls and 14 domains into these four themes and added 11 new controls, including threat intelligence, cloud services security, data masking and secure coding.
What are the seven ISO 19011:2018 audit principles?
Integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach. The risk-based approach was added in the 2018 revision. Following these principles helps independent auditors reach consistent, reliable audit conclusions.
Explore More CQI and IRCA Auditor Training Exams
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.