Question 1 of 30
Compliance review shows that the organization\'s incident management process is a key area for the ISO 27001 audit. The auditor needs to gather evidence to assess the effectiveness of the controls implemented for handling security incidents. Which of the following approaches would be the most effective and professionally sound for evidence collection in this scenario?
Review documented incident reports and logs, and then conduct interviews with key personnel involved in incident response to corroborate findings.
Request a complete dump of all server logs for the past year without a specific focus on particular incident types.
Solely rely on interviews with the IT security manager to understand the incident management process.
Observe the IT team during a simulated incident response exercise without reviewing any prior incident documentation.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free