Question 1 of 30
During the evaluation of an organization\'s ISMS, a new cloud-based customer relationship management (CRM) service is introduced. This service will store sensitive customer data and interact with existing in-scope sales and marketing systems. The organization\'s current ISMS scope covers its on-premises IT infrastructure and core business applications. The IT department proposes to exclude the new CRM service from the ISMS scope, citing its cloud-based nature and separate management by the vendor, while the security team advocates for its inclusion due to the sensitive data it handles and its integration with existing systems. What is the most appropriate approach for the Lead Auditor to take regarding the ISMS scope in this situation?
Recommend that the ISMS scope be extended to include the new CRM service, provided a thorough impact assessment demonstrates that its integration introduces new or altered risks to the organization's information assets, or that it is essential for achieving the organization's information security objectives.
Recommend that the new CRM service be excluded from the ISMS scope because it is a new addition and managed by a third-party vendor, assuming the vendor has its own security certifications.
Recommend that the new CRM service be included in the ISMS scope without further assessment, to ensure maximum coverage and avoid any potential security gaps.
Recommend that the new CRM service be excluded from the ISMS scope because it is a cloud-based service and therefore inherently managed by the vendor, and the organization's current ISMS scope is sufficient for its on-premises infrastructure.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free