Question 1 of 30
An ISO 27002:2022 Lead Auditor is conducting a surveillance audit for a financial services firm. During the review of the risk treatment register, the auditor identifies that the documented treatment plan for a critical zero-day vulnerability, discovered six months prior, has not been reviewed or updated since its initial implementation. The organization\'s policy mandates a quarterly review of all critical risk treatment plans. What is the most appropriate immediate action for the Lead Auditor?
Document a nonconformity related to the failure to adhere to the organization's own policy for risk treatment plan review and investigate the underlying reasons for this oversight.
Recommend that the organization immediately update the risk treatment plan and schedule a follow-up audit specifically for this issue.
Focus the audit scope on other areas to avoid disrupting the organization's immediate remediation efforts for the vulnerability.
Advise the organization to implement a new control that mandates automated reminders for all risk treatment plan reviews.

Preparing for ISO 27002:2022 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free