nerdexam
PECB

LEAD-AUDITOR · Question #139

Which one of the following options best describes the purpose of a Stage 2 audit?

The correct answer is C. To evaluate the implementation of the management system. The purpose of a Stage 2 audit is to evaluate the implementation of the management system, in this case, the ISMS, according to the requirements of ISO/IEC 27001:2022 and the organisation's own policies and procedures. The Stage 2 audit involves collecting evidence of the effecti

Audit Types and Objectives

Question

Which one of the following options best describes the purpose of a Stage 2 audit?

Options

  • ATo check for legal compliance by the organisation
  • BTo ensure that the audit plan is carried out
  • CTo evaluate the implementation of the management system
  • DTo get to know the organisation's processes

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    7% (3)
  • C
    86% (37)
  • D
    2% (1)

Explanation

The purpose of a Stage 2 audit is to evaluate the implementation of the management system, in this case, the ISMS, according to the requirements of ISO/IEC 27001:2022 and the organisation's own policies and procedures. The Stage 2 audit involves collecting evidence of the effectiveness and performance of the ISMS, as well as verifying the conformity and suitability of the organisation's controls. The Stage 2 audit also assesses the organisation's ability to achieve its information security objectives and to manage information security risks.

Topics

#Stage 2 audit#management system evaluation#audit purpose#implementation

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice