The Stage 2 audit focuses on:
- A.Reviewing only the risk assessment. This corresponds to Annex A control 7.2 under the 2022 structure, with a different numbering under the 2013 Annex A.
- B.Only reviewing documentation. Annex A control 5.30 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with external auditors rather than with the process owner named in the question.
- C.Providing consulting advice
- D.Evaluating the implementation and effectiveness of the ISMS in practice
Why D is correct
Stage 2 evaluates whether the ISMS is implemented, operating effectively, and achieving its objectives in practice.
Know someone studying for ISO 27001? Send them this one.