Question 1 of 30
Operational review demonstrates that the information security management system (ISMS) for a financial services organization is undergoing its annual internal audit. The auditor needs to verify the effectiveness of the access control policy for sensitive customer data. Which of the following evidence collection methods would be the most appropriate and comprehensive for this specific objective?
Reviewing the documented access control policy and interviewing the IT security manager about its implementation.
Observing the process of granting and revoking access to sensitive customer data, interviewing key personnel involved in access management, and reviewing system logs of access events.
Accepting the IT security manager's assurance that the access control policy is being followed diligently by all staff.
Examining historical access logs from the past two years to identify any past breaches or unauthorized access attempts.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free