Question 1 of 30
The risk matrix shows a number of high-priority risks related to data breaches and system outages. As the ISO 27001 Lead Auditor, you are tasked with defining the scope of the upcoming internal audit. Considering the organization has recently undergone a significant digital transformation, including the adoption of new cloud services and remote working policies, which of the following approaches best defines the scope of the internal audit?
Focus the audit scope exclusively on the high-priority risks identified in the current risk matrix, ensuring all controls related to these risks are thoroughly examined.
Broaden the audit scope to include not only the high-priority risks from the matrix but also areas impacted by the recent digital transformation, such as the security of new cloud services and the effectiveness of remote access controls, as these represent potential new or amplified risks.
Prioritize auditing areas with the highest number of documented security controls, as this indicates a strong focus on security and likely requires less intensive review.
Limit the audit scope to areas that have not been audited in the last two audit cycles, regardless of their current risk profile or recent changes.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free