According to the ISACA CISA Study Guide, the primary focus of an IS auditor when evaluating the response process for cyber crimes should be evidence collection. This is because the investigation and resolution of cyber incidents rely heavily on the evidence that is collected and analyzed. For more information, please refer to the ISACA CISA Study Guide section 4.13.2.2.