ISO-IEC-27001-LEAD-AUDITOR · Question #181
Which one of the following options best describes the purpose of a Stage 2 audit?
The correct answer is C. To evaluate the implementation of the management system. The purpose of a Stage 2 audit is to evaluate the implementation of the management system, in this case, the ISMS, according to the requirements of ISO/IEC 27001:2022 and the organisation's own policies and procedures. The Stage 2 audit involves collecting evidence of the…
Question
Which one of the following options best describes the purpose of a Stage 2 audit?
Options
- ATo check for legal compliance by the organisation
- BTo ensure that the audit plan is carried out
- CTo evaluate the implementation of the management system
- DTo get to know the organisation's processes
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- C88% (22)
- D4% (1)
Explanation
The purpose of a Stage 2 audit is to evaluate the implementation of the management system, in this case, the ISMS, according to the requirements of ISO/IEC 27001:2022 and the organisation's own policies and procedures. The Stage 2 audit involves collecting evidence of the effectiveness and performance of the ISMS, as well as verifying the conformity and suitability of the organisation's controls. The Stage 2 audit also assesses the organisation's ability to achieve its information security objectives and to manage information security risks.
Topics
Community Discussion
No community discussion yet for this question.