6.2 Interviewing Techniques and Open-Ended Querying
Key Takeaways
- Effective interviewing requires a strategic mix of open and closed questions to gather comprehensive information and verify specific facts.
- Active listening is essential for auditors to understand the auditee's perspective, identify non-verbal cues, and follow up on critical points.
- Handling difficult auditees requires professionalism, patience, and a steadfast focus on objective evidence rather than personal dynamics.
The Art of the Audit Interview
Interviews are among the most critical methods for gathering objective evidence during an ISMS audit. While reviewing documents and observing processes are essential, interviews provide the context necessary to understand how the Information Security Management System operates in reality. Documents show what should happen; interviews reveal what actually happens. Mastering interviewing techniques is, therefore, a core competency for any lead auditor. This section delves into the nuances of questioning, the imperative of active listening, and strategies for navigating difficult interactions.
Open vs. Closed Questions
The structure of the questions an auditor asks dictates the quality and depth of the information received. A skilled auditor employs a strategic mix of open and closed questions, navigating the interview to elicit both broad narratives and specific facts.
Open-Ended Questions: These are the primary tools for exploration. Open questions typically begin with 'How', 'What', 'Why', 'Describe', or 'Explain'. They cannot be answered with a simple 'yes' or 'no'. The objective is to encourage the auditee to speak freely, describe processes in their own words, and reveal their understanding of the ISMS requirements.
Example: 'Can you describe the process you follow when a new employee joins the organization and requires access to the CRM system?'
By asking an open question, the auditor invites the auditee to walk through the workflow. The auditor listens for key control points, such as authorization steps, role-based access assignments, and documentation of the request. The narrative provided by the auditee often yields unexpected insights and highlights areas that require further investigation.
Closed-Ended Questions: Once a narrative has been established, the auditor must verify specific details. This is where closed questions are deployed. Closed questions are designed to elicit a specific, often binary, response (e.g., 'yes', 'no', 'three', 'John Doe'). They are used to confirm facts, seek clarification, or narrow down a broad topic.
Example: 'Did the system owner approve this specific access request for Jane Doe on March 15th?'
While crucial for verification, overusing closed questions can make the interview feel like an interrogation. It limits the auditee's ability to provide context and can cause them to become defensive. The ideal rhythm involves using an open question to gather a narrative, followed by targeted closed questions to verify the specifics of that narrative against the objective evidence.
The Funnel Technique
A highly effective method for structuring an interview is the funnel technique. The auditor begins at the wide end of the funnel with broad, open-ended questions to establish the general process (e.g., 'Tell me about your vulnerability management program'). As the auditee provides the narrative, the auditor listens for key controls and then progressively narrows the focus using more specific open questions (e.g., 'How do you prioritize the vulnerabilities identified in the monthly scan?'). Finally, at the narrow end of the funnel, the auditor uses closed questions to verify precise details against the evidence (e.g., 'Did you patch the critical Apache vulnerability on server X within the 48-hour SLA?'). This structured approach ensures thorough coverage while maintaining a conversational tone.
Active Listening
Formulating the right questions is only half of the interviewing equation; the other half is active listening. Active listening requires the auditor to fully concentrate, understand, respond, and then remember what is being said. It is an exhausting but necessary practice.
Key Components of Active Listening in Auditing:
- Undivided Attention: The auditor must minimize distractions, maintain appropriate eye contact, and focus entirely on the auditee. Constantly looking at a laptop or audit checklist signals disinterest and can stifle the conversation.
- Non-Verbal Cues: A significant portion of communication is non-verbal. The auditor should observe the auditee's body language. Hesitation, defensiveness, or nervous gestures when discussing a particular topic can indicate areas of weakness that warrant deeper investigation.
- Paraphrasing and Summarizing: To ensure accurate understanding, the auditor should periodically paraphrase what the auditee has said. For instance, 'So, if I understand correctly, the IT support desk creates the account only after receiving the ticket approved by the department manager. Is that accurate?' This confirms the auditor's comprehension and allows the auditee to correct any misunderstandings.
- Silence: Silence is a powerful auditing tool. After asking a question, the auditor should wait patiently for the answer. Many people are uncomfortable with silence and will fill the void with additional information, often providing valuable context that would not have been elicited otherwise.
Note-Taking Strategies
Taking accurate notes during an interview is critical, but it can also be disruptive if not handled correctly. An auditor who spends the entire interview staring at their notepad or typing furiously on a laptop creates a barrier between themselves and the auditee. To mitigate this, auditors should practice efficient note-taking, focusing on keywords, dates, names, and specific document references rather than attempting to transcribe the conversation verbatim. It is also helpful to explain the note-taking process at the beginning of the interview: 'I will be taking notes while we speak to ensure I capture your processes accurately. Please do not let it distract you.' Periodically pausing to review notes and summarize key points back to the auditee demonstrates active listening and allows for immediate correction of any inaccuracies.
Handling Difficult Auditees
Auditors interact with a wide variety of personalities. While most auditees are cooperative, some may be difficult, defensive, or even hostile. The auditor's ability to maintain professionalism and control the interview in these situations is paramount.
Types of Difficult Auditees and Strategies:
- The Talker: This individual answers a simple question with a ten-minute monologue, often diverging into irrelevant topics. Strategy: The auditor must gently but firmly interrupt and redirect the conversation. 'Thank you, that is very helpful background. To bring us back to the specific requirement, could you show me...'
- The Silent Type: This auditee provides monosyllabic answers and volunteers no additional information. Strategy: Rely heavily on open-ended questions. Avoid rapid-fire closed questions, which will only cause them to withdraw further. Use silence to encourage them to elaborate.
- The Defensive or Aggressive Auditee: This individual may challenge the auditor's competence, argue about the interpretation of the standard, or become visibly angry. Strategy: Remain calm, objective, and unflappable. Do not engage in an argument. Bring the focus back to the objective evidence and the specific text of the ISO/IEC 27001 standard. If the situation escalates, take a break, involve the audit guide, or escalate the issue to the lead auditor or management.
Ultimately, the goal of an audit interview is not to catch the auditee doing something wrong, but to gather sufficient, reliable evidence to evaluate the effectiveness of the ISMS. By mastering open-ended querying, practicing active listening, and expertly managing interpersonal dynamics, the auditor transforms the interview from a simple Q&A session into a powerful instrument for uncovering the true state of information security within the organization.
Which of the following is the best example of an open-ended question designed to evaluate an organization's incident response process?
How should an auditor utilize silence during an interview?
An auditee continuously provides long, rambling answers that stray far from the topic being audited. What is the most appropriate technique for the auditor to employ?