Question 1 of 30
Market research demonstrates that organizations often struggle with the practical application of audit principles during information security audits. An ISO 27001 Lead Auditor is reviewing the effectiveness of access controls for a critical system. During the audit, the auditor observes a user account that appears to be inactive for an extended period, based on the last login timestamp. However, the auditor does not have immediate access to system logs that definitively confirm the account\'s current operational status or the reason for the inactivity. What is the most appropriate course of action for the auditor to take in accordance with ISO 27001 audit principles?
Request access to relevant system logs or interview the system administrator to gather further evidence and context regarding the account's status before concluding on its compliance with access control policies.
Immediately document a non-conformity regarding the inactive user account, assuming it represents a security risk due to potential unauthorized access or misuse.
Dismiss the observation entirely, as there is no immediate, definitive proof of a policy violation, and focus on other audit areas to maintain audit efficiency.
Formulate a personal opinion on the likely reason for the inactivity and report this as a potential area of concern without seeking further verification.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free