Question 1 of 30
The performance metrics show a significant increase in the number of security incidents reported over the last quarter. Considering the impact assessment process used to define information security objectives, which of the following actions is the most appropriate for an ISO 27001 Lead Auditor to recommend regarding the organization\'s information security objectives?
Recommend a review of the information security objectives to determine if they remain relevant and achievable in light of the increased incident rate, and if the impact assessment process adequately considered such trends.
Advise the organization to simply increase the number of implemented security controls to mitigate the rising incident rate, without revisiting the objectives.
Suggest that the increased incident rate is likely an anomaly and does not necessitate a re-evaluation of the existing information security objectives.
Recommend focusing solely on the quantitative reduction of incident numbers as the primary measure of success, disregarding the underlying impact assessment that defined the original objectives.