Question 1 of 30
Risk assessment procedures indicate a strong correlation between identified high-priority risks and the organization\'s stated ISMS objectives. However, upon review, these objectives are phrased as broad statements such as \"Enhance data confidentiality\" and \"Improve incident response effectiveness.\" As an ISO 27001 Lead Auditor, what is the most appropriate course of action?
Recommend that the organization refine its information security objectives to be specific, measurable, achievable, relevant, and time-bound (SMART) to ensure they are auditable and demonstrably contributing to risk reduction.
Accept the stated objectives as sufficient, given their direct linkage to the risk assessment findings, and proceed with auditing the controls related to those risks.
Advise the organization to abandon the current objectives and develop entirely new ones based on a fresh risk assessment.
Focus the audit solely on the technical controls implemented to address the identified risks, as the objectives themselves are not directly auditable.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free