nerdexam
PECB

LEAD-AUDITOR · Question #115

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of…

The correct answer is D. I will ensure that appropriate measures have been introduced to inform top management as to the F. I will check that threat intelligence is actively used to protect the confidentiality, integrity and G. I will review how information relating to information security threats is collected and evaluated to. You've hit your limit · resets 4am (America/New_York)

Information Security Controls

Question

You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's application of control 5.7 - Threat Intelligence. They are aware that this is one of the new controls introduced in the 2022 edition of ISO/IEC 27001, and they want to make sure they audit the control correctly. They have prepared a checklist to assist them with their audit and want you to confirm that their planned activities are aligned with the control's requirements. Which three of the following options represent valid audit trails?

Options

  • AI will ensure that the task of producing threat intelligence is assigned to the organisation's internal
  • BI will ensure that the organisation's risk assessment process begins with effective threat
  • CI will speak to top management to make sure all staff are aware of the importance of reporting
  • DI will ensure that appropriate measures have been introduced to inform top management as to the
  • EI will check that the organisation has a fully documented threat intelligence process
  • FI will check that threat intelligence is actively used to protect the confidentiality, integrity and
  • GI will review how information relating to information security threats is collected and evaluated to
  • HI will determine whether internal and external sources of information are used in the production of

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    5% (1)
  • D
    70% (14)
  • E
    15% (3)

Explanation

You've hit your limit · resets 4am (America/New_York)

Topics

#threat intelligence#ISO 27001:2022 control 5.7#new controls 2022#audit checklist

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice