Soru

Zorluk: OrtaSecurity Audits, Assessments, and Attestations

A software technology vendor has established a formal Information Security Management System (ISMS) to safeguard its cloud services. To satisfy international enterprise clients requiring proof of security compliance and receive an officially recognized certificate, the vendor must undergo an independent third-party evaluation. Which of the following activities should the vendor initiate?

  1. An ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification bodyCevap
  2. B
    An internal security attestation review performed by the vendor's chief information security officer
  3. C
    A self-administered PCI DSS Self-Assessment Questionnaire to evaluate overall governance controls
  4. D
    A third-party vulnerability assessment without an accompanying control design and operational audit

Cevap

An ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification body
The correct answer specifies an ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification body. ISO/IEC 27001 certification requires a two-stage independent audit: Stage 1 reviews documentation readiness, and Stage 2 assesses the actual operational effectiveness and compliance of the Information Security Management System (ISMS) to grant official certification.

Adım Adım Çözüm

1
Identify the organizational objective described in the scenario
The vendor needs an officially recognized international security certification for its overall Information Security Management System (ISMS).
Enterprise clients require independent verification that security governance aligns with recognized international standards.
2
Evaluate the requirement for auditor independence and audit scope
Self-assessments and internal reviews lack external independence, while technical vulnerability scans only evaluate technical asset posture rather than holistic ISMS processes.
Formal attestation and certification require an accredited external certification body to perform a comprehensive audit.
3
Select the deliverable that matches formal ISMS certification
An ISO/IEC 27001 Stage 2 audit is the formal evaluation step where an accredited Registrar verifies operational compliance and grants official certification.
Stage 2 audits evaluate the effective implementation of controls within the ISMS framework.

Anahtar Kavram

Independent Third-Party Audits and Security Certifications
Bu soruyu puanla