Type: Practical Audit Simulation Marks: 100 Time: 4-6 hours
You are the Lead Auditor conducting a Stage 2 certification audit of FinTech Secure Ltd., a company providing payment gateway services.
Review the following evidence items collected during the audit:
Item 1: During an interview, the HR Manager confirms that background checks are performed on all new hires. However, a review of 10 recent employee files shows that 3 files are missing the background check documentation.
Item 2: The Information Security Policy was last reviewed and signed by the CEO three years ago.
Item 3: The organization's risk register identifies "Unauthorized physical access to the server room" as a high risk. The risk treatment plan states that a biometric lock will be installed. During the site tour, the auditor observes a standard key lock on the server room door.
Item 4: The organization conducts annual penetration testing. The most recent report identified 5 critical vulnerabilities. A review of the IT ticketing system shows that all 5 were patched within 48 hours of the report being issued.
For each of the 4 evidence items above:
- Classify it as Conformity, Nonconformity, or Opportunity for Improvement.
- If it is a Nonconformity, write a formal Nonconformity Report using the PLO structure (Provision, Location, Objective Evidence).
Based on your findings in Task 1, write a formal Audit Conclusion. Will you recommend FinTech Secure Ltd. for ISO/IEC 27001 certification? Justify your decision based on the severity of the findings.
Assume you raised a Major Nonconformity for Item 3 (the server room lock). The auditee submits the following Corrective Action Plan: "We have ordered the biometric lock and it will be installed next week." Evaluate this CAP using the Five-Question Test. Will you accept or reject it? Justify your answer.
Prepare an agenda and brief speaking notes for the Closing Meeting with the CEO of FinTech Secure Ltd. Outline how you will present your findings and conclusions.