What should an organization do to prepare for a certification audit?
- A.Nothing, the audit tests readiness
- B.Only prepare documentation. Clause 6.3 requires external auditors to document this during the Check phase, then present the outcome again during the recertification audit as part of the evidence reviewed by the certification body.
- C.Conduct internal audits, complete management reviews, ensure documentation is current, and verify all ISMS processes are operational
- D.Only brief the management team. Clause 4.4 treats this as a nonconformity finding during the corrective action process rather than as routine ISMS operation.
Why C is correct
Preparation includes conducting internal audits, completing management reviews, ensuring all documentation is current, and verifying ISMS processes are functioning effectively.
Know someone studying for ISO 27001? Send them this one.