Question 1 of 30
The risk matrix shows a moderate risk rating for the client\'s cloud storage solution, but the Statement of Applicability lists several critical security controls for this area. The audit team is pressed for time and needs to finalize the audit plan. Which approach best ensures compliance with ISO 27001:2022 and effective ISMS auditing?
Focus the audit plan on areas with high risk ratings in the matrix, as these represent the most immediate threats.
Prioritize auditing the cloud storage solution due to the critical controls listed in the Statement of Applicability, even if its risk rating is moderate, and supplement with other high-risk areas as time permits.
Exclude the cloud storage solution from the detailed audit plan, assuming the moderate risk rating implies it is adequately managed, and focus solely on the highest risk items identified in the matrix.
Conduct a high-level review of all areas with moderate risk ratings in the matrix, including the cloud storage solution, to ensure broad coverage without deep dives.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free