Expert Advice Community

Guest

Questions to top management

  Quote
Guest
Guest user Created:   Mar 13, 2019 Last commented:   Mar 13, 2019

Questions to top management

What are the top questions the auditor can ask to the top of information security management ? 10 questions needed.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 13, 2019

Answer:

In fact you do not need 10 questions for top management regarding information security, because they do not need to have deep knowledge of information security to properly support it. These are the main questions you should consider asking them:
- Which benefits you understand information security management brings to your company?
- How information security objectives support business objectives?
- By which means do you support information security practices in your company?

Of course you can expand these questions to fulfill your needs (e.g., specific questions about communicating the information security policy and the realization of management review).

These articles will provide you further explanation about top management and ISO 27001:
- Roles and responsibilities of top management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/06/09/roles-and-responsibilities-of-top-management-in- iso-27001-and-iso-22301/
- Four key benefits of ISO 27001 implementation https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/
- ISO 27001 control objectives – Why are they important? https://advisera.com/27001academy/blog/2012/04/10/iso-27001-control-objectives-why-are-they-important/
- Top management perspective of information security implementation https://advisera.com/27001academy/blog/2012/12/04/top-management-perspective-of-information-security-implementation/
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
- Infographic: The brain of an ISO auditor – What to expect at a certification audit https://advisera.com/articles/infographic-the-brain-of-an-iso-auditor-what-to-expect-at-a-certification-audit/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 13, 2019

Mar 13, 2019

Suggested Topics

Guest user Created:   Jan 09, 2019 ISO 27001 & 22301
Replies: 1
0 0

Questions to top management

Ash Created:   Jan 21, 2024 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 Internal Audits

Guest user Created:   May 13, 2023 ISO 27001 & 22301
Replies: 1
0 0

Risk Register & BYOD