ISO 27001: the auditor's three questions

Free

If your company is ISO 27001 certified, an auditor may question you. The standard expects everyone to know three things: where the security policy is, how they contribute, and what happens if it isn't followed.

  • 3 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Know where to find your company's security policy and name one or two rules that apply to your job
  • Describe your own contribution to security through concrete actions
  • Know the consequences of not following it, for the company and for yourself

The module

3 min
  1. ISO 27001: the auditor's three questions 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • ISO/IEC 27001:2022, § 7.3 (sensibilisation) et A.6.3
  • ISO/IEC 17021-1:2015, § 9.1.3 (audits de surveillance au moins une fois par année civile)
  • Verizon, 2026 Data Breach Investigations Report, mai 2026 (facteur humain : 62 % des violations)

Version 1 · updated October 4, 2026