nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #76

Which one of the following statements best describes the purpose of conducting a document review?

The correct answer is C. To determine the conformity of the management system, as far as documented, with audit criteria. A document review is a process of examining the documented information related to the management system before the on-site audit activities. The purpose of a document review is to: 12 Determine the conformity of the management system, as far as documented, with audit criteria…

Audit Evidence Collection and Verification

Question

Which one of the following statements best describes the purpose of conducting a document review?

Options

  • ATo reveal whether the documented management system is nonconforming with audit criteria and
  • BTo decide about the conformity of the documented management system with audit standards and
  • CTo determine the conformity of the management system, as far as documented, with audit criteria
  • DTo detect any nonconformity of the management system, if documented, with audit criteria and to

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    85% (35)
  • D
    10% (4)

Explanation

A document review is a process of examining the documented information related to the management system before the on-site audit activities. The purpose of a document review is to: 12 Determine the conformity of the management system, as far as documented, with audit criteria, i.e., to check whether the documents are consistent, complete, and compliant with the requirements of ISO/IEC 27001 and any other applicable standards or regulations. Gather information to support the on-site audit activities, i.e., to identify the scope, objectives, processes, controls, risks, and opportunities of the management system, and to plan the audit methods, techniques, and resources accordingly.

Topics

#document review#audit criteria#management system documentation#conformity assessment

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice