Question 1 of 30
During the evaluation of an organization\'s information security management system (ISMS) for ISO 27001:2022 compliance, the auditor is assessing the evidence of leadership commitment. The organization has a formally documented information security policy signed by the CEO. The auditor has also spoken with the information security manager who stated that the CEO is very supportive of information security initiatives. What is the most effective way for the auditor to verify the extent of leadership commitment?
Review meeting minutes of the management review process and action logs to identify instances where leadership has discussed, made decisions on, or allocated resources for information security objectives and risks.
Accept the documented information security policy as sufficient evidence of leadership commitment, as it is a formal declaration.
Rely on the verbal assurance from the information security manager that the CEO is supportive, as this reflects the operational perception.
Examine the number of security awareness training sessions conducted, assuming this is a direct indicator of leadership's prioritization of security.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free