ISO-IEC-27001-LEAD-AUDITOR · Question #56
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of…
The correct answer is A. I will review the organisation's threat intelligence process and will ensure that this is fully D. I will check that threat intelligence is actively used to protect the confidentiality, integrity and F. I will determine whether internal and external sources of information are used in the production of. According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), control 5.7 requires an organization to establish and maintain a threat intelligence process…
Question
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of control 5.7 - Threat Intelligence. They are aware that this is one of the new controls introduced in the 2022 edition of ISO/IEC 27001, and they want to make sure they audit the control correctly. They have prepared a checklist to assist them with their audit and want you to confirm that their planned activities are aligned with the control's requirements. Which three of the following options represent valid audit trails?
Options
- AI will review the organisation's threat intelligence process and will ensure that this is fully
- BI will speak to top management to make sure all staff are aware of the importance of reporting
- CI will ensure that the task of producing threat intelligence is assigned to the organisation s internal
- DI will check that threat intelligence is actively used to protect the confidentiality, integrity and
- EI will ensure that the organisation's risk assessment process begins with effective threat
- FI will determine whether internal and external sources of information are used in the production of
- GI will review how information relating to information security threats is collected and evaluated to
- HI will ensure that appropriate measures have been introduced to inform top management as to the
How the community answered
(40 responses)- A48% (19)
- B3% (1)
- C25% (10)
- E8% (3)
- G5% (2)
- H13% (5)
Explanation
According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), control 5.7 requires an organization to establish and maintain a threat intelligence process to identify and evaluate information security threats that are relevant to its ISMS scope and objectives1. The organization should use internal and external sources of information, such as vulnerability databases, threat feeds, industry reports, etc., to produce threat intelligence that can be used to support risk assessment and treatment, as well as other information security activities1. Therefore, when auditing the organization's application of control 5.7, an ISMS auditor should verify that these aspects are met in accordance with the audit criteria. Three options that represent valid audit trails for verifying control 5.7 are: I will review the organisation's threat intelligence process and will ensure that this is fully documented: This option is valid because it can provide evidence of how the organization has established and maintained a threat intelligence process that is consistent with its ISMS scope and objectives. It can also verify that the process is documented according to clause 7.5 of ISO/IEC 27001:20221. I will check that threat intelligence is actively used to protect the confidentiality, integrity and availability of the organisation's information assets: This option is valid because it can provide evidence of how the organization has used threat intelligence to support its risk assessment and treatment, as well as other information security activities, such as incident response, awareness, or monitoring. It can also verify that the organization has achieved its information security objectives according to clause 6.2 of ISO/IEC 27001:20221. I will determine whether internal and external sources of information are used in the production of threat intelligence: This option is valid because it can provide evidence of how the organization has used various sources of information, such as vulnerability databases, threat feeds, industry reports, etc., to produce threat intelligence that is relevant and reliable. It can also verify that the organization has complied with the requirement of control 5.7 of ISO/IEC 27001:20221.
Topics
Community Discussion
No community discussion yet for this question.