Exam ISO-IEC-27001-Lead-Auditor Topic 1 Question 335 Discussion
Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 335
Topic #: 1
Question #: 335
Topic #: 1
Scenario 8
[Scenario text identical to Question 69]
Question
Following the initial audit, when is a surveillance audit typically conducted?
[Scenario text identical to Question 69]
Question
Following the initial audit, when is a surveillance audit typically conducted?
Suggested Answer: B Vote an answer
The correct answer is during the first and second years of certification, making option B correct. According to ISO/IEC 17021-1, ISO/IEC 27006, and standard certification cycle rules, ISO/IEC 27001 certification follows a three-year certification cycle. After the initial certification audit, the organization is subject to periodic surveillance audits to ensure continued conformity of the ISMS.
Surveillance audits are typically conducted annually during the first and second years following certification.
Their purpose is to verify that the ISMS remains effective, that corrective actions are maintained, and that the organization continues to comply with ISO/IEC 27001 requirements. These audits are less extensive than the initial certification audit but still cover critical ISMS elements, changes, incidents, and improvement activities.
Option A is incorrect because surveillance audits are mandatory and scheduled by the certification body, not optional or request-based. Option C is incorrect because five years exceeds the standard certification cycle.
Instead, a recertification audit is conducted in the third year, not a surveillance audit.
Therefore, surveillance audits are normally conducted during the first and second years after certification, confirming option B as correct.
Surveillance audits are typically conducted annually during the first and second years following certification.
Their purpose is to verify that the ISMS remains effective, that corrective actions are maintained, and that the organization continues to comply with ISO/IEC 27001 requirements. These audits are less extensive than the initial certification audit but still cover critical ISMS elements, changes, incidents, and improvement activities.
Option A is incorrect because surveillance audits are mandatory and scheduled by the certification body, not optional or request-based. Option C is incorrect because five years exceeds the standard certification cycle.
Instead, a recertification audit is conducted in the third year, not a surveillance audit.
Therefore, surveillance audits are normally conducted during the first and second years after certification, confirming option B as correct.
by Gail at Jul 30, 2026, 12:19 AM
Contact Us
If you have any question please leave me your email address, we will reply and send email to you in 12 hours.
Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday
Support: Contact now
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).