Auditing the Risk Assessment and the Statement of Applicability

5 minutes 5 Questions

In an ISO/IEC 27001 audit, the risk assessment and the Statement of Applicability (SoA) are central evidence that the ISMS is risk-based rather than a checklist exercise. A Lead Auditor examines them together because the SoA should follow logically from risk assessment and treatment decisions. When…

Test mode:
More Auditing the Risk Assessment and the Statement of Applicability questions
27 questions (total)