Clause 10 of ISO 27001 is the “Act” part of Deming’s Plan-Do-Check-Act cycle. Once you have “checked” the performance of your system (as per Clause 9) you then use Clause 10 to act on the findings.
Meeting this clause will provide real value for your business. When you record non-conformances, implement some great corrective actions and continuously improve how you do things, you are significantly upping your game. Clause 10 is a potential game changer for your business.
Let’s start with 10.1 Nonconformity and corrective action.
The ISO 27003 guidance document describes the types of non-conformance that you should be recording in your ISMS. There are a shed-load of them:
Now that is a lot. And at the start it can seem overwhelming. But once you knock the non-conformances off with great corrective actions, it gets easier and easier.
The secret? Record everything!
For example, here at Mango we record every information security incident reported by the New Zealand Government’s cyber security department CERTNZ. These are things like:
You should engage with your own country’s cyber security agency and start recording all of the threats to your business.
Next up, you need to put some corrective action in place to correct or protect yourself from these threats or non-conformances.
The guidance standard has some handy steps to address nonconformities. There is always some immediate short-term correction you can take to handle the situation, and these are:
Now that you have the non-conformance in hand, you can put in some long-term corrective action. Once again ISO 27003 provides valuable advice about corrective actions:
The standard requires you to keep document information (or records) as evidence that the non-conformities and subsequent actions have been taken, as well as the results of any corrective action that are also taken.
For example, here at Mango we use the Improvement module that has a workflow that records the implementation of corrective action using the stages described above. It makes meeting this clause oh so easy.
Finally clause 10.2 has a requirement to continuously improve the ISMS.
Here at Mango we are continually talking about the ISMS. It is a topic of discussion in all our processes and all our meetings. It has become second nature.
We are constantly looking at making improvements. It’s a mindset. It’s not just a requirement of our ISMS. It’s what we do around here.
In addition, we have a great forum that we use to get the message to all staff. Our monthly all-staff Management Review meetings discuss all of the ISMS improvements that are happening. This is great for showing leadership, communication, participation and culture. You should try and do the same.
View previous blogs in this series "ISO 27001 Information Security Management Standard":
Part 1 - Reasons why you need to meet this standard
Part 2 - Principle 1 - Analysing the Protection of Your Information and then Applying Controls
Part 3 - Principle 2 - Awareness of the Need for Information Security
Part 4 - Principle 3 - Assignment of Responsibility for Information Security
Part 5 - Principle 4 - Incorporating Management Commitment and the Interests of Stakeholders
Part 6 - Principle 5 - Enhancing Societal Values
Part 9 - Principle 8 - Active prevention and detection of information security incidents
Part 10 - Principle 9 - Ensuring a comprehensive approach to information security management
Part 12 - ISO 27001 Information Security Management Standard: Clauses 0, 0.1, 0.2, 1, 2 and 3
Part 13 - ISO 27001 Information Security Management Standard: Clauses 4.1, 4.2, 4.3 and 4.4
Part 14 - ISO 27001 Information Security Management Standard: Clause 5.1
Part 15 - ISO 27001 Information Security Management Standard: Clause 5.2
Part 16 - ISO 27001 Information Security Management Standard: Clause 5.3
Part 17 - ISO 27001 Information Security Management Standard: Clause 6.1
Part 18 - ISO 27001 Information Security Management Standard: Clause 6.2
Part 19 - ISO 27001 Information Security Management Standard: Clause 7.1 - 7.4
Part 20 - ISO 27001 Information Security Management Standard: Clause 7.5
Part 21 - ISO 27001 Information Security Management Standard: Clause 8.1, 8.2, 8.3
Part 22 - ISO 27001 Information Security Management Standard: Clause 9.1, 9.2, 9.3