Question 1 of 30
Regulatory review indicates that during an ISO 27001 audit, an auditor discovers a significant technical vulnerability that, if exploited, could lead to unauthorized disclosure of sensitive customer data. The client\'s senior representative, who is overseeing the audit, attempts to persuade the auditor to exclude this finding from the formal audit report, citing potential reputational damage and suggesting it is a low-priority issue that will be addressed \"internally later.\" The auditor is confident in the severity of the vulnerability and its direct impact on the confidentiality of information. What is the most appropriate course of action for the auditor?
Document the vulnerability with its potential impact on confidentiality and report it to the designated client management as a nonconformity, following the audit plan's reporting procedures.
Agree to the client representative's request and omit the finding from the report to maintain a positive client relationship and avoid immediate conflict.
Immediately escalate the finding to external regulatory authorities without informing the client or the auditor's own management.
Ignore the finding and proceed with the audit, assuming the client will address it independently at a later time.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free