A security analyst is preparing for an annual audit against ISO/IEC 27001. The auditor has requested evidence of the organization's incident management process, specifically how improvements are identified and implemented. Which of the following metrics or reporting elements would BEST demonstrate adherence to the 'continual improvement' aspect of ISO 27001's incident management?
- ANumber of security incidents reported per quarter.
- BTotal budget allocated to incident response tools.
- CTrend analysis of root causes and corresponding control enhancements implemented.
- DMean Time To Detect (MTTD) for all incidents.
Show answer & explanationAnswer & explanation
Correct answer: C. Trend analysis of root causes and corresponding control enhancements implemented.
ISO 27001's Clause A.16.1.7 (Collecting evidence) and the overall PDCA (Plan-Do-Check-Act) cycle emphasize continual improvement. A trend analysis of root causes coupled with implemented control enhancements directly demonstrates that the organization is learning from incidents, identifying systemic issues, and actively improving its security posture, which is the essence of continual improvement.
Why the other options are wrong
- A. This metric shows incident volume but not how the organization is improving its response or prevention.
- B. Budget allocation reflects investment but not the actual outcome or effectiveness of improvement processes.
- D. MTTD shows detection efficiency but not the process of learning from incidents and implementing improvements.
ISO 27001 Continual Improvement (Incident Management)
ISO 27001 requires organizations to continually improve the suitability, adequacy, and effectiveness of their Information Security Management System (ISMS), including incident management, often demonstrated through root cause analysis and subsequent control enhancements.
- Aligned with the PDCA (Plan-Do-Check-Act) cycle.
- Focuses on learning from incidents to prevent recurrence.
- Requires documentation of improvements and their impact.
Memory trick: ISO: Improve Security Continuously, Learn from Incidents.