Module 11 Flashcards
Audit
1
Q
what are the mandatory documents in an audit according to ISO27001?
A
- Scope of the ISMS
- Infosec Policy
- Risk assessment and treatment methodology
- SoA
- Risk Treatment plan
- Risk ASsessment report
- Definition of security roles and responsibilties
- Inventory of assets
2
Q
when do audit findings have to be fixed?
A
criticial: immediately
prio 1: within 2 weeks
prio 2: within 3 months