nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #154

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of…

The correct answer is D. I will ensure that appropriate measures have been introduced to inform top management as to the F. I will check that threat intelligence is actively used to protect the confidentiality, integrity and G. I will review how information relating to information security threats is collected and evaluated to. These three options represent valid audit trails for control 5.7, as they are aligned with the control's requirements and objectives. According to the web search results from my predefined tool, control 5.7 requires organisations to collect and analyse information relating to…

ISMS Controls and Annex A

Question

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of control 5.7 - Threat Intelligence. They are aware that this is one of the new controls introduced in the 2022 edition of ISO/IEC 27001, and they want to make sure they audit the control correctly. They have prepared a checklist to assist them with their audit and want you to confirm that their planned activities are aligned with the control's requirements. Which three of the following options represent valid audit trails?

Options

  • AI will ensure that the task of producing threat intelligence is assigned to the organisation's internal
  • BI will ensure that the organisation's risk assessment process begins with effective threat
  • CI will speak to top management to make sure all staff are aware of the importance of reporting
  • DI will ensure that appropriate measures have been introduced to inform top management as to the
  • EI will check that the organisation has a fully documented threat intelligence process
  • FI will check that threat intelligence is actively used to protect the confidentiality, integrity and
  • GI will review how information relating to information security threats is collected and evaluated to
  • HI will determine whether internal and external sources of information are used in the production of

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    23% (12)
  • C
    6% (3)
  • D
    56% (29)
  • E
    10% (5)
  • H
    4% (2)

Explanation

These three options represent valid audit trails for control 5.7, as they are aligned with the control's requirements and objectives. According to the web search results from my predefined tool, control 5.7 requires organisations to collect and analyse information relating to information security threats and use that information to take mitigation actions12. The control also specifies that threat intelligence should be relevant, perceptive, contextual, and actionable, and that it should be used to prevent, detect, or respond to threats34. Therefore, the auditor should verify how the organisation collects, analyses, and produces threat intelligence, how it uses threat intelligence to protect its information assets, and how it monitors and evaluates the effectiveness of its threat intelligence arrangements.

Topics

#threat intelligence#control 5.7#ISO 27001:2022#audit checklist validation

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice