Question 1 of 30
The review process indicates that following a recent significant data breach, the organization has logged the incident but has not conducted a formal assessment of the breach\'s impact on its information security objectives, contractual obligations, or overall business operations. Which of the following actions by the Lead Auditor best addresses this situation in accordance with ISO 27001 Lead Auditor principles?
Escalate the finding to senior management, highlighting the need for a comprehensive impact assessment as required by Clause 9.1, and recommend the initiation of a formal process to evaluate the breach's consequences and inform risk treatment.
Document the lack of an impact assessment as a minor observation, assuming the incident response team will address it as part of their ongoing operational activities.
Advise the organization to immediately implement specific technical security patches without first understanding the full scope of the breach's impact.
Conclude that the incident logging process is sufficient and no further action is required from an audit perspective, as the breach has already been recorded.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free