What is one of the responsibilities of an internal auditor?
A. Determine and ensure the provision of all necessary resources for the audit.
B. Prepare the organization for external audits.
C. Schedule the frequency of internal audits.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which of the following is a discussion-based exercise?
A. Desktop
B. Full-scale exercise
C. Functional exercise
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Scenario:
NexTech Innovations, a dynamic tech startup located in Seoul, South Korea, is renowned for its advancements in artificial intelligence and robotics. Serving a global clientele, NexTech encountered a sudden obstacle when a critical supplier abruptly ceased operations, disrupting their supply chain and threatening their ability to deliver products on schedule. Recognizing the need for resilience, NexTech initiated the implementation of a robust business continuity management system (BCMS) based on ISO 22301.
NexTech's top management established a project team of five members and appointed Rebecca, the lead operations manager, as the project manager. The BCM team was tasked with the effective implementation of the BCMS in line with ISO 22301 requirements. Rebecca worked with the top management to analyze the internal context of the company to define the BCMS scope, focusing on assessing and determining who is responsible for coordinating and managing activities at different organizational levels.
The project team divided the implementation project into smaller tasks, identifying the personnel, equipment, and materials needed for each. Rebecca personally handled resource allocation to implement and support the BCMS. Meanwhile, the top management ensured active involvement and commitment at all levels of the organization to enhance the BCMS's effectiveness.
Rebecca and the team drafted and published the business continuity policy on the company's website.
However, some employees found the technical jargon challenging to understand, so comprehensive training sessions were held to address this issue. These measures strengthened NexTech's resilience and enhanced client trust by proactively addressing potential disruptions.
Rebecca and the BCM team drafted, published, and communicated the business continuity policy on the organization's website. Was this course of action in accordance with best practices?
A. No, the policy should have been communicated officially to the relevant parties rather than publishing it on the website.
B. No, the project team must obtain formal approval for the policy before publication.
C. Yes, it is the project team's responsibility to draft and publish the policy the moment it is ready for communication.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Scenario:
Headquartered in Sri Lanka, Operons Inc. is a freight forwarding company that adopted a BCMS aligned with ISO 22301. Prior to the certification audit, Operons Inc. measured gaps between their BCMS and the standard's requirements to ensure compliance. The certification body was contracted to conduct the audit, and a biased auditor from a previous ISO 9001 audit was replaced upon request. During the audit, two minor nonconformities were identified, and the audit team issued a recommendation for certification.
In Scenario 8, the certification body accepts Operons Inc.'s rejection of the auditor and appoints another one.
Is this acceptable?
A. Yes, previously displayed unprofessional conduct is a valid reason to replace an auditor.
B. No, the auditor can be rejected only if a conflict of interest situation is present.
C. Yes, the auditor has previously audited the company against ISO 9001, which is a valid reason for replacing the auditor.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Scenario:
Prebank is a multinational financial institution. Its services include banking and investing through banking centers, ATMs, and mobile banking platforms. With millions of clients, Prebank's database systems record vast amounts of data and transactions daily. Its main activities depend on the ability of its employees to access clients' data through its database system at any time.
Recently, Prebank's database system stopped working unexpectedly. Soon after, it was discovered that this disruption was caused by the maintenance work on the road outside the company's office building. During the road repair, the workers had unintentionally damaged a water pipe that leaked into Prebank's basement. This leakage affected the company's electrical infrastructure, resulting in a loss of power, which shut down equipment and computers in the server room. Consequently, employees were unable to access Prebank's database system.
After this incident, the employees immediately notified Prebank's IT team. Subsequently, the IT team informed both the maintenance company responsible for the roadworks and the insurance company. The company responsible for maintenance told Prebank's IT team that the maintenance team was not available for the day. Since Prebank did not have a plan for responding to similar disruptions, they had to stop working and go home. Thankfully, the maintenance team arrived at the scene on the next day and made all the necessary repairs, allowing Prebank to resume all its operations.
Following these events, Prebank decided to change its strategy and procedures to prioritize businesscontinuity planning within the company. Its main focus was to address the root cause of disruptions to improve business continuity. As such, the top management decided to implement a Business Continuity Management System (BCMS) based on ISO 22301.
After setting the company's business continuity objectives, the company established a project team, including a project manager and four additional team members. The BCM team was responsible for managing the BCMS implementation process, whereas the top management was responsible for the effectiveness of the BCMS. Through analyzing potential risk scenarios, the team defined Prebank's business continuity strategy as well as the resources for supporting business continuity within the company. This enabled the team to predict the impact of disruptions caused by various incidents, such as power outages. Following these actions, the company established a business continuity plan to manage disruptions effectively without impacting the workflow.
The effective implementation of the BCMS helped Prebank not only minimize losses and ensure continuity in its services but also absorb and adapt to a changing environment.
Which of the following statements regarding disaster recovery is correct?
A. It minimizes operational downtime.
B. It minimizes ineffective system function.
C. It ensures effective communication during a disaster.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
What is a characteristic of internal audits?
A. They have no advisory role within the organization.
B. They are always conducted yearly.
C. They are independent of the audited activities (not of the organization).
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Scenario:
NexTech Innovations, a dynamic tech startup located in Seoul, South Korea, is renowned for its advancements in artificial intelligence and robotics. Serving a global clientele, NexTech encountered a sudden obstacle when a critical supplier abruptly ceased operations, disrupting their supply chain and threatening their ability to deliver products on schedule. Recognizing the need for resilience, NexTech initiated the implementation of a robust business continuity management system (BCMS) based on ISO 22301.
NexTech's top management established a project team of five members and appointed Rebecca, the lead operations manager, as the project manager. The BCM team was tasked with the effective implementation of the BCMS in line with ISO 22301 requirements. Rebecca worked with the top management to analyze the internal context of the company to define the BCMS scope, focusing on assessing and determining who is responsible for coordinating and managing activities at different organizational levels.
The project team divided the implementation project into smaller tasks, identifying the personnel, equipment, and materials needed for each. Rebecca personally handled resource allocation to implement and support the BCMS. Meanwhile, the top management ensured active involvement and commitment at all levels of the organization to enhance the BCMS's effectiveness.
Rebecca and the team drafted and published the business continuity policy on the company's website.
However, some employees found the technical jargon challenging to understand, so comprehensive training sessions were held to address this issue. These measures strengthened NexTech's resilience and enhanced client trust by proactively addressing potential disruptions.
Rebecca allocated the necessary resources for implementing and supporting the BCMS. Is this in compliance with ISO 22301?
A. No, it is the top management's responsibility to allocate the resources needed for the BCMS.
B. Yes, it is the project manager's responsibility to allocate resources for the management system.
C. No, resource allocation for the BCMS should be delegated to a resource allocation team, not the project manager alone.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
What does ISO 22313 provide?
A. Specific requirements for the planning, establishment, implementation, and monitoring of the BCMS.
B. Requirements for bodies providing audit and certification of BCMS.
C. Guidance and recommendations to continue the delivery of products and services at an acceptable capacity during a business disruption.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
Esaki -
今回のISO-22301-Lead-Implementerの問題集の内容もすごくわかりやすくて素敵です。また買いに来ます。