What does ISO/IEC 27001:2022 require for internal audits?
A.
A person designated by top management who can perform internal audits in all areas within the system scope
B.
Acquisition of a set of information security tools to document internal audits
C.
Conducting internal audits at planned intervals to provide information on whether the Information Security Management System conforms to the organization’s own requirements and to the requirements of ISO/IEC 27001:2022
D.
A consultancy to perform second-party internal audits accurately
The Answer Is:
C
This question includes an explanation.
Explanation:
ISO/IEC 27001:2022 requires the organization to conduct internal audits at planned intervals. These audits must determine whether the ISMS conforms to the organization’s own requirements for its ISMS and to the requirements of the standard, and whether the ISMS is effectively implemented and maintained. The standard does not require a specific tool, consultant, or one designated person to audit every area. Therefore, option C is correct.
I27001F PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"