🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor82 / 148
Question 82 of 148
An IS auditor is reviewing an organization's implementation of ISO/IEC 27001. The security manager states that certain Annex A controls were excluded because they were not relevant to the business. Which document should the auditor examine FIRST to determine whether these exclusions are justified and properly authorized?
Reviewed for accuracy · Report an issueNext question