Question 1 of 30
The audit findings indicate that while the organization has conducted a comprehensive information security risk assessment and documented numerous security controls, the established information security objectives appear to be generic statements about maintaining confidentiality, integrity, and availability, without a clear, demonstrable link to the specific risks identified or the strategic business goals of the organization. Which of the following approaches best addresses this finding in accordance with ISO 27001?
Verify that the information security objectives are directly derived from the identified risks and risk treatment plan, are measurable, and demonstrably contribute to the achievement of the organization's strategic business objectives.
Assess the technical implementation and operational effectiveness of the documented security controls to ensure they are functioning as intended.
Review the organization's compliance with each individual clause of ISO 27001, focusing on the documentation of objectives as required by Clause 6.2.
Confirm that a formal information security risk assessment has been performed and that information security objectives have been documented, assuming a natural alignment.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free