Question 1 of 30
The investigation demonstrates that while an information security policy exists, it does not explicitly mandate a formal impact assessment process for the introduction of new technologies, leading to potential unmitigated risks. Which of the following actions by the ISO 27001 Lead Auditor best addresses this deficiency?
Recommend that the organization revise its information security policy to include a mandatory requirement for a formal information security impact assessment for all new technology introductions, and ensure this assessment is integrated into the technology procurement and implementation lifecycle.
Note the absence of an explicit impact assessment requirement in the policy as a minor nonconformity, assuming that departmental risk assessments will adequately cover new technologies.
Advise the organization to create a separate document detailing the impact assessment process for new technologies, independent of the information security policy.
Conclude that the existing information security policy is sufficient as long as the organization has a general risk management framework in place, even if it doesn't specifically address technology introductions.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free