Nonconformity and corrective action
When a nonconformity or a significant incident occurs, react, investigate the root cause and implement the necessary corrective action.
Continual improvement
Continually improve the suitability and effectiveness of the ISMS, updating the risk analysis whenever threats or context change.
What an auditor usually asks for
- A security nonconformity log recording root cause
- Documented verification that each corrective action was effective
- An updated risk analysis after significant incidents
- An ISMS improvement plan with concrete actions
How to cover improvement in Kimobox
- 1Open every security nonconformity with a mandatory root cause.
- 2Assign the corrective action to an owner and a date, flagged if it runs late.
- 3Verify the action's effectiveness and update the risk analysis if needed.
Every security incident stays linked to its cause, its action and its effectiveness check.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024