Question 1 of 30
Quality control measures reveal that an ISO 27001 Lead Auditor is reviewing the effectiveness of access control mechanisms within a financial services organization. The auditor observes that while the implemented access control system is functional and prevents unauthorized access, it is an older, proprietary system that is not the latest technology available on the market. The auditor also notes that the system\'s operational costs are higher than some newer, commercially available alternatives. The auditor is tasked with determining if the current controls meet the key principles of information security. Which of the following approaches best reflects the auditor\'s professional responsibility in this scenario?
Assess the effectiveness of the current access control system in protecting confidential, integrity, and available information assets against identified risks, and evaluate its alignment with the organization's risk appetite, regardless of its age or cost relative to newer technologies.
Recommend immediate replacement of the access control system with a newer, more cost-effective solution, as the current system is outdated and potentially inefficient, even if it currently meets basic security requirements.
Focus primarily on ensuring that the access control procedures are meticulously documented and followed, as this demonstrates compliance with the standard's requirements for access control management.
Prioritize the reduction of operational costs associated with the access control system, suggesting that any security gaps created by cost-saving measures can be addressed through compensating controls later.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free