Question 1 of 30
An internal auditor is evaluating an organization\'s adherence to ISO 27032:2012. During the audit, it is observed that while the organization possesses advanced technical defenses against common cyber threats and has a detailed incident response plan, there is a notable absence of a formally documented cybersecurity policy that explicitly links cyber risk management to strategic business objectives. Furthermore, employee training on cybersecurity awareness is sporadic and not tailored to specific roles, and there are no established channels for sharing threat intelligence with external industry partners. Which of the following findings represents the most significant gap in relation to the foundational principles and guidance provided by ISO 27032:2012?
The lack of a formally documented cybersecurity policy that explicitly integrates cyber risk management with overarching business objectives and the absence of role-specific, consistent cybersecurity awareness training.
The absence of established channels for sharing threat intelligence with external industry partners, as this limits the organization's ability to contribute to collective cybersecurity efforts.
The presence of advanced technical defenses and a detailed incident response plan, which indicates a strong operational capability despite policy and training deficiencies.
The sporadic nature of employee cybersecurity awareness training, which, while important, is less critical than the technical and procedural controls in place.

Preparing for ISO 27032:2012 Internal Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free