Our own servers in Europe · GDPR · Support in your language

Module 7 of 7 · ISO 27001 · Clause 10

Improvement

The final clause closes the loop: what happens after a security nonconformity, and how that turns into a more robust system.

Content reviewed on

Nonconformity and corrective action

When a nonconformity or a significant incident occurs, react, investigate the root cause and implement the necessary corrective action.

Continual improvement

Continually improve the suitability and effectiveness of the ISMS, updating the risk analysis whenever threats or context change.

What an auditor usually asks for

  • A security nonconformity log recording root cause
  • Documented verification that each corrective action was effective
  • An updated risk analysis after significant incidents
  • An ISMS improvement plan with concrete actions

How to cover improvement in Kimobox

  1. 1Open every security nonconformity with a mandatory root cause.
  2. 2Assign the corrective action to an owner and a date, flagged if it runs late.
  3. 3Verify the action's effectiveness and update the risk analysis if needed.

Every security incident stays linked to its cause, its action and its effectiveness check.

See nonconformities and corrective actions in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024