nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #169

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of…

The correct answer is A. I will determine whether internal and external sources of information are used in the production of D. I will check that the organisation has a fully documented threat intelligence process E. I will check that threat intelligence is actively used to protect the confidentiality, integrity and. The options that represent valid audit trails for assessing the organisation's application of control 5.7 - Threat Intelligence, according to ISO/IEC 27001:2022, are: Option A: I will determine whether internal and external sources of information are used in the production of…

Information Security Controls Auditing

Question

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of control 5.7 - Threat Intelligence. They are aware that this is one of the new controls introduced in the 2022 edition of ISO/IEC 27001, and they want to make sure they audit the control correctly. They have prepared a checklist to assist them with their audit and want you to confirm that their planned activities are aligned with the control's requirements. Which three of the following options represent valid audit trails?

Options

  • AI will determine whether internal and external sources of information are used in the production of
  • BI will ensure that the task of producing threat intelligence is assigned to the organisation's internal
  • CI will ensure that the organisation's risk assessment process begins with effective threat
  • DI will check that the organisation has a fully documented threat intelligence process
  • EI will check that threat intelligence is actively used to protect the confidentiality, integrity and
  • FI will speak to top management to make sure all staff are aware of the importance of reporting
  • GI will ensure that appropriate measures have been introduced to inform top management as to the
  • HI will review how information relating to information security threats is collected and evaluated to

How the community answered

(37 responses)
  • A
    76% (28)
  • C
    5% (2)
  • F
    3% (1)
  • G
    3% (1)
  • H
    14% (5)

Explanation

The options that represent valid audit trails for assessing the organisation's application of control 5.7 - Threat Intelligence, according to ISO/IEC 27001:2022, are: Option A: I will determine whether internal and external sources of information are used in the production of threat intelligence. This is relevant because effective threat intelligence typically requires gathering information from multiple sources to be comprehensive. Option D: I will check that the organisation has a fully documented threat intelligence process. Proper documentation is a core requirement in ISO standards to ensure processes are defined, implemented, and maintained consistently. Option E: I will check that threat intelligence is actively used to protect the confidentiality, integrity, and availability of the organisation's information assets. This verifies that the output of threat intelligence is being used effectively within the organisation's information security practices.

Topics

#threat intelligence#ISO/IEC 27001:2022 new controls#audit checklist#control 5.7

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice