Question 1 of 30
To address the challenge of verifying the effectiveness of an organization\'s information security risk assessment process as part of an ISO 27001 Lead Auditor engagement, which evidence collection method would best demonstrate that identified risks are being systematically evaluated and managed according to the organization\'s risk appetite?
Conducting interviews with key personnel involved in the risk assessment process and reviewing documented risk assessment reports, including evidence of risk treatment decisions and residual risk acceptance.
Observing general security practices across various departments and noting any apparent adherence to security policies.
Reviewing a broad range of general operational procedures and policies unrelated to specific identified risks.
Interviewing IT security staff to gauge their technical understanding of implemented security controls.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free