ISO 27001: the auditor's three questions
Free
If your company is ISO 27001 certified, an auditor may question you. The standard expects everyone to know three things: where the security policy is, how they contribute, and what happens if it isn't followed.
- 3 min
- 3-question check
- English · Français
- Attestation
You will be able to
- Know where to find your company's security policy and name one or two rules that apply to your job
- Describe your own contribution to security through concrete actions
- Know the consequences of not following it, for the company and for yourself
The module
3 min-
ISO 27001: the auditor's three questions 2 min
-
Knowledge check
3 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Sources
- ISO/IEC 27001:2022, § 7.3 (sensibilisation) et A.6.3
- ISO/IEC 17021-1:2015, § 9.1.3 (audits de surveillance au moins une fois par année civile)
- Verizon, 2026 Data Breach Investigations Report, mai 2026 (facteur humain : 62 % des violations)
Version 1 · updated October 4, 2026