Question 1 of 30
Governance review demonstrates that a critical project, currently in its development phase, has not yet produced a final, formal information security risk assessment report. However, project documentation indicates that initial threat modeling and vulnerability assessments have been conducted, and preliminary risk treatment measures are being integrated into the project plan. As an ISO 27001 Lead Auditor, how should you proceed to assess the information security posture of this project?
Verify that the project team has followed the organization's established information security risk management process, including the identification of threats and vulnerabilities, assessment of potential impacts, and the implementation or planning of appropriate risk treatment measures, even in the absence of a final report.
Conclude that the project is non-compliant due to the absence of a final, formal risk assessment report, and recommend immediate cessation of project activities until such a report is finalized.
Focus solely on the general information security policies of the organization and assume that their application to the project is adequate without specific project-level verification.
Defer the assessment of this project's information security risks until the project is fully operational and a complete risk assessment can be performed.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free