Which one of the following options describes the main purpose of a Stage 1 audit?

Which one of the following options describes the main purpose of a Stage 1 audit?
A . To determine readiness for Stage 2
B . To check for legal compliance by the organisation
C . To get to know the organisation
D . To compile the audit plan

Answer: A

Explanation:

The main purpose of a Stage 1 audit is to evaluate the adequacy and effectiveness of the organisation’s ISMS documentation, and to assess whether the organisation is prepared for the Stage 2 audit, where the implementation and operation of the ISMS will be verified. The Stage 1 audit also involves verifying the scope, objectives, and context of the ISMS, as well as identifying any areas of concern or nonconformities that need to be addressed before the Stage 2 audit.

Reference: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) objectives and content from Quality.org and PECB

ISO/IEC 27006:2015 Information technology ― Security techniques ― Requirements for bodies providing audit and certification of information security management systems Section 7.3.1

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments