Expert Advice Community

Guest

IT audits and CISO

  Quote
Guest
Guest user Created:   Jul 20, 2016 Last commented:   Jul 20, 2016

IT audits and CISO

Good day, does the IT auditor audits the work of the information security officer?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
Antonio Jose Segovia Jul 20, 2016

Answer:
I am not sure if I have understood 100% your question, but the CISO (Chief Information Security Officer) generally performs activities related to the implementation and maintenance of the ISO 27001 standard, and these activities should be reviewed during the ISO 27001 internal audit.

But if your question is about IT audits (ethical hacking, penetration testing, etc), from my point of view it is not necessary to review the work of the CISO, you simply need to review the configuration of systems, open ports, services running, etc.

This article can be interesting for you “What is the job of Chief Information Security Office (CISO) in ISO 27001?” : https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/

Finally, our online course can be also interesting for you because we giv e more information about the internal audit “ISO 27001:2013 Internal Auditor Course” : https://advisera.com/training/iso-27001-internal-auditor-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 19, 2016

Jul 19, 2016

Suggested Topics

Guest user Created:   Mar 19, 2021 ISO 27001 & 22301
Replies: 3
0 0

ISO 27001 questions

Guest user Created:   Feb 09, 2021 ISO 27001 & 22301
Replies: 1
0 0

Control A.14.3.1

Guest user Created:   Dec 17, 2022 ISO 27001 & 22301
Replies: 1
0 0

Questions ISO 27001