Question 1 of 30
Stakeholder feedback indicates that while the organization has a documented Information Security Policy and a designated Information Security Officer, operational teams perceive a lack of proactive engagement and strategic direction from top management regarding information security matters. As an ISO 27001 Lead Auditor, which approach would be most effective in assessing the reality of leadership and commitment to the ISMS?
Conduct interviews with key personnel across different levels of the organization, review evidence of management review meetings where strategic decisions regarding information security are made and acted upon, and assess how leadership communicates information security objectives and responsibilities.
Focus solely on verifying the existence and currency of the documented Information Security Policy and confirming the appointment of an Information Security Officer.
Assume that the allocation of a budget for information security initiatives by top management inherently demonstrates sufficient leadership commitment.
Rely exclusively on the audit team's initial assessment of the ISMS documentation without seeking corroborating evidence from stakeholders or management.