Module 11 Flashcards

Audit

1
Q

what are the mandatory documents in an audit according to ISO27001?

A
  1. Scope of the ISMS
  2. Infosec Policy
  3. Risk assessment and treatment methodology
  4. SoA
  5. Risk Treatment plan
  6. Risk ASsessment report
  7. Definition of security roles and responsibilties
  8. Inventory of assets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

when do audit findings have to be fixed?

A

criticial: immediately
prio 1: within 2 weeks
prio 2: within 3 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly