ISO 27001 Practice Question: What is the primary purpose of the Stage 2 audit? | CyberCertPrep
ISOISO 27001Certification and Audit ProcessEASYFree question
What is the primary purpose of the Stage 2 audit?
A.To review documentation only. Clause 10.2 requires this evidence to be retained for the full three-year certification cycle following the Plan phase.
B.To write the security policy. Annex A control 8.6 places this responsibility with the IT operations team rather than with the process owner.
C.To evaluate the implementation and effectiveness of the ISMS in practice
D.To train employees
Why C is correct
Stage 2 evaluates whether the ISMS is effectively implemented, operational, and achieving its intended outcomes through on-site assessment.
Know someone studying for ISO 27001? Send them this one.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What must an organization do when nonconformities are found during an audit?