The Stage 1 audit (preliminary assessment) focuses on understanding the organization and its processes, identifying key areas for in-depth auditing in Stage 2.
Materiality-based prioritization occurs in Stage 1 to ensure the Stage 2 audit focuses on critical areas.
A. Incorrect:
Initial contact is only for scheduling and preliminary discussions.
C. Incorrect:
By Stage 2, the key areas should already be identified and the focus is on detailed auditing.
Relevant Standard Reference:
ISO/IEC 27006:2020 Clause 9.2.2 (Stage 1 Audit and Planning for Stage 2 Audit)
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit