According to ISO/IEC 27001 controls, when planning audit tests and assurance activities involving operational systems, who should be involved in the agreement process except the tester?
Answer is "B" "Implement the change: the appointed person implements the change; however, there may be another level of authority for approving and incorporating the change in the organization’s operational activities (e.g., the ISMS coordinator). The scale and nature of the change (and perhaps of the organization) should determine who approves the implemented change."
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
DashRyde
2 months, 1 week ago