The documented results of an intrusion-detection test from an information security expert from an external organization
B.
A defined sample analysis of nonconformity reports drafted by the audited organization from the time their ISMS was implemented
C.
An interview with the information security personnel to validate if the information security process complies with the standard requirements
The Answer Is:
C
This question includes an explanation.
Explanation:
Qualitative evidence in an audit typically involves observations, interviews, and reviews that provide insights into the processes and compliance through subjective but informed assessments. An interview with information security personnel to validate compliance with the standard requirements is an example of qualitative evidence, where the quality and effectiveness of processes are assessed based on expert judgments rather than measurable metrics.
[References: PECB ISO/IEC 27001 Lead Auditor Course Material, , ]
ISO-IEC-27001-Lead-Auditor PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"