Question 1 of 30
The risk matrix shows a critical control failure related to data access, and during the audit, the Information Security Officer states they are unsure if the responsibility for implementing the compensating control lies with them or the IT Operations Manager. What is the most appropriate action for the ISO 27001 Lead Auditor to take?
Document the uncertainty as a non-conformity against Clause 5.3, "Organizational roles, responsibilities and authorities," and recommend a review of the ISMS documentation and communication processes.
Advise the Information Security Officer to consult their manager to clarify their responsibilities before the audit concludes.
Assume the responsibility lies with the IT Operations Manager, as they typically manage IT infrastructure, and proceed with the audit.
Note the individual's lack of clarity but consider it a minor issue as long as the compensating control is eventually implemented, regardless of who is responsible.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free