Question 1 of 30
Benchmark analysis indicates that an organization\'s risk identification process relies heavily on reviewing past security incidents. During an ISO 27001 Lead Auditor examination, which of the following approaches to assessing the effectiveness of this risk identification technique would be most professionally challenging and require the deepest analysis to determine its adequacy?
Evaluating the technique's ability to identify potential future risks that have not yet manifested as incidents, by exploring hypothetical scenarios and their potential consequences.
Verifying that the organization has a documented procedure for reviewing historical security incidents.
Assessing the frequency with which historical incidents have occurred in the past year.
Confirming that the organization has allocated sufficient resources for incident response based on past data.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free