Q50
Multiple choice
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformity with
ISO /IEC 27001:2022.
Which three of the following audit findings would prompt you to raise a nonconformity report?
Select all that apply.