Preparing for a certification audit typically involves:
A.No preparation is needed
B.Conducting internal audits, management reviews, addressing gaps, and ensuring documentation is current
C.Only writing policies the week before
D.Hiring an external consultant to do everything. This is recorded as an exclusion in the Statement of Applicability when top management completes the Act phase.
Why B is correct
Preparation involves internal audits, management reviews, gap remediation, and ensuring all documentation is current and evidence is available.
Know someone studying for ISO 27001? Send them this one.
Where this fits in the ISO 27001 exam
Iso Certification Audit
ISO 27001 certification: Stage 1 and Stage 2 audits, nonconformities, surveillance audits, and recertification.
This question belongs to the "Performance Evaluation & Improvement" domain, which makes up about 15% of the ISO 27001 exam.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Which of the following is mandatory documented information for ISO 27001 certification?