Nonconformity and continual improvement
Clause 10 requires organizations to react to failures in the Information Security Management System (ISMS) by correcting them and preventing their recurrence through root cause analysis. It also mandates a systematic approach to constantly enhancing the effectiveness and maturity of the ISMS over time.
What it means
In practice, this clause establishes a feedback loop for the entire security system. When a "nonconformity" occurs—which is any instance where a requirement of the standard, your own internal policies, or legal obligations are not met—you cannot simply apply a quick fix. You must determine why the failure happened and change the underlying process to ensure it does not happen again.
Continual improvement is broader than just fixing errors. It requires the organization to use data from risk assessments, internal audits, and management reviews to proactively evolve the ISMS. The goal is to move the security posture from a state of "compliance" to a state of increasing maturity and resilience.
How to meet it
- Establish a formal process for identifying, documenting, and reporting nonconformities (e.g., a ticket system or log).
- Implement a Root Cause Analysis (RCA) procedure to investigate why a failure occurred rather than just treating the symptom.
- Define a workflow for "Corrective Actions" that includes assigning ownership, setting deadlines, and implementing changes to policies or controls.
- Create a mechanism to verify the effectiveness of corrective actions after they have been implemented to ensure the problem has actually been solved.
- Use the outputs of Management Reviews and Internal Audits as primary inputs for identifying areas where the ISMS can be improved.
- Set measurable security improvement objectives for each cycle (e.g., reducing the time to detect incidents or increasing staff training completion rates).
Evidence an auditor asks for
- A Nonconformity and Corrective Action Log/Tracker showing identified issues, their root causes, actions taken, and closure dates.
- Documentation of Root Cause Analysis for significant security incidents or audit failures.
- Management Review meeting minutes that explicitly discuss "continual improvement" and result in actionable decisions.
- Internal Audit reports paired with evidence of the subsequent remediation plans implemented to address findings.
Common pitfalls
- Confusing "correction" with "corrective action." A correction is fixing a mistake (e.g., deleting an unauthorized user); a corrective action is fixing the process that allowed the mistake to happen (e.g., updating the onboarding/offboarding policy).
- Failing to document the "effectiveness review," leaving the auditor with no proof that the implemented fix actually worked.
- Treating continual improvement as a vague concept rather than a documented set of activities driven by data and management decisions.