Auditing Internal Audit and Management Review

5 minutes 5 Questions

In an ISO/IEC 27001 certification audit, the Lead Auditor must verify that the organization's Information Security Management System (ISMS) can evaluate and improve itself. Two key mechanisms are Internal Audit (Clause 9.2) and Management Review (Clause 9.3). Auditing them shows whether top managem…

Test mode:
More Auditing Internal Audit and Management Review questions
27 questions (total)