問題文
An audit team is assembling the audit criteria for the certification audit of a payment processor. Besides the standard, the organization is bound by a national data protection law, a card scheme contract, and its own internal information security policy. How should the audit team leader treat those three items?
選択肢
- They are overriding rules the standard yields, so they outrank the audit criteria and swapping is planned for each of them.
- They are market background the organization occupies, so they influence the audit criteria and nothing is planned for each of them.
- They are legal matters the department validates, so they leave the audit criteria and confirmation is planned for each of them.
- They are compliance requirements the organization undertook, so they join the audit criteria and evidence is planned for each of them.