Question 1 of 30
Consider a scenario where an organization has documented its information security objectives as \"Enhance employee vigilance against phishing attacks\" and \"Maintain a robust incident response capability.\" As an ISO 27001 Lead Auditor, which of the following approaches best demonstrates due diligence in verifying the effectiveness of these objectives?
Requesting evidence of specific metrics used to measure the reduction in successful phishing attempts and the timeliness of incident response, and assessing if these metrics align with the organization's risk appetite and strategic goals.
Accepting the objectives as stated, assuming that the organization's management has adequately defined them and that their implementation is implicitly contributing to overall security.
Reviewing the training materials provided to employees on phishing awareness and the documented incident response plan, without verifying specific performance indicators or their alignment with strategic objectives.
Focusing solely on the existence of a documented incident response plan and phishing awareness training program, without delving into the measurability or strategic relevance of the stated objectives.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free