Question 1 of 30
Process analysis reveals that an organization has identified a significant risk of unauthorized access to sensitive customer data due to a legacy system lacking robust authentication mechanisms. The organization proposes to implement a compensating control by increasing the frequency of manual log reviews and relying on user reporting for suspicious activity, rather than upgrading the legacy system or implementing multi-factor authentication. As an ISO 27001 Lead Auditor, how should you evaluate this risk treatment option?
Assess whether the compensating controls adequately reduce the risk to an acceptable level, considering the organization's risk appetite and the feasibility of the proposed controls, and verify their inclusion and justification in the Statement of Applicability.
Accept the proposed risk treatment option as it involves manual log reviews and user reporting, which are common security practices, and therefore likely to be effective.
Focus primarily on the cost-effectiveness of the proposed compensating controls, ensuring they are less expensive than upgrading the legacy system or implementing multi-factor authentication.
Conclude that the risk treatment is acceptable because the proposed controls are mentioned as potential security measures in general information security literature, even if not explicitly detailed in ISO 27001 Annex A.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free