ISO 27001 Practice Question: What is a surveillance audit? | CyberCertPrep
ISOISO 27001Certification and Audit ProcessEASYFree question
What is a surveillance audit?
A.Monitoring employee behavior. Clause 9.2 requires this evidence to be retained for the full three-year certification cycle following the corrective action process.
B.A surprise inspection
C.A customer audit. Annex A control 5.36 governs this obligation instead of the clause implied by the question.
D.An annual audit conducted between certification cycles to verify the ISMS continues to be effective
Why D is correct
Surveillance audits are conducted annually between certification cycles to verify the ISMS continues to meet requirements and is being maintained.
Know someone studying for ISO 27001? Send them this one.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What must an organization do when nonconformities are found during an audit?