CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard
An organization is preparing for an external audit of its information security management system (ISMS). The audit will assess compliance with ISO/IEC 27001. Which of the following activities is MOST crucial for the organization to complete BEFORE the audit to demonstrate adherence to the standard?
- AEnsuring all employees have completed annual security awareness training.
- BPerforming an internal audit to verify the effectiveness of controls and processes.
- CImplementing a new Security Information and Event Management (SIEM) system.
- DConducting a penetration test of all public-facing applications.
Show answer & explanationAnswer & explanation
Correct answer: B. Performing an internal audit to verify the effectiveness of controls and processes.
ISO/IEC 27001 explicitly requires regular internal audits (Clause 9.2) to ensure the ISMS conforms to the organization's own requirements and the standard's requirements, and that it is effectively implemented and maintained. This is a crucial prerequisite for an external certification audit.
Why the other options are wrong
- A. Security awareness training is a control required by ISO 27001 (A.7.2.2), but demonstrating its effectiveness and the overall ISMS function via an internal audit is more critical for audit readiness.
- C. Implementing a SIEM system is a technical control (A.12.4.1) that can aid in security but is not a mandatory or singularly crucial activity for demonstrating overall ISMS compliance for an ISO 27001 audit compared to an internal audit.
- D. Penetration testing is an important control but not the *most crucial* activity to demonstrate overall ISMS adherence for an ISO 27001 audit, which focuses on the management system itself.
Internal Audit (ISO 27001)
A systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the ISMS audit criteria are fulfilled.
- Mandatory requirement of ISO 27001 (Clause 9.2).
- Verifies ISMS conformity and effectiveness.
- Prepares the organization for external certification audits.
Memory trick: To 'Pass ISO', 'Internal Audit' is the 'Key Check'.