Improvement for ISO 27001 Requirements 10.1 - 10.2
What is covered under Section 10 of ISO 27001:2013?
Section 10 addresses how you will improve your ISMS on an ongoing basis.
ISO 27001, like many other ISO standards, is concerned with continual improvement. Given the speed of change in many
Falling under Sect.10 is:
ISO 27001 Section 10.1 – Nonconformity and corrective action
Section 10.1 of27001 concerns the actions your organisation commits to taking when a failure in the compliance of the occurs. The refers to this as a ‘nonconformity’ and the steps you take to correct this is called a ‘corrective action’.
In the event of a nonconformity, the organisation should ‘take action to control and correct it’, and deal with the consequences of the event. They should then take steps to ensure that it doesn’t happen again. This is done by addressing the cause of the nonconformity.
The corrective action should be assessed and the effectiveness of that action, measured and documented.
Remember, to obtain and maintain ISO 27001 certification, an auditor will expect to see evidence of improvements. It is not a failure to show you are addressing nonconformities, taking corrective actions etc so do make sure that they are visible if appropriate to demonstrate the philosophy of continuous improvement that is required by the standard.
How to demonstrate nonconformities and corrective actions are being addressed
Using ISMS.online software to manage your ISMS will give you access to not just a policy for 10.1, but also the Corrective Actions & Improvement Track which has been built for you to quickly and simply demonstrate and evidence the work being done. It is customised ready to use immediately and will help you manage the corrective actions and improvements you identify through a standard workflow process. You will be able to assign actions to team members, set due dates, and join-up your ISMS by linking it quickly to other areas, such as a policy or control which may need updating.
ISO 27001 Section 10.2 – Continual improvement
A large part of running an information security management system is to see it as a living and breathing thing. Your
There are several mechanisms covered within ISO 27001 for the continual evaluation and improvement of your ISMS including audits, management reviews, the corrective actions and improvements process, ongoing risk assessment, ongoing staff engagement etc. The secret is not to waste time duplicating work that is going on in the wider ISMS in order to easily demonstrate continual improvement is taking place.
How to demonstrate the
organisation is continually improving the suitability, adequacy, and effectiveness of the ISMS
This is a great example of how the ISMS
Again, ISMS.online comes with a Policy for 10.2 which already includes links to the areas where you will be able to quickly demonstrate continual improvement is embedded in your
Expert guidance on meeting the requirements of Sect 10. is included in our optional ISO 27001 Virtual Coach.
ISO 27001 Annex A Controls
- A.5 Information security policies
- A.6 Organisation of information security
- A.7 Human resource security
- A.8 Asset management
- A.9 Access control
- A.10 Cryptography
- A.11 Physical and environmental security
- A.12 Operations security
- A.13 Communications security
- A.14 System acquisition, development, and maintenance
- A.15 Supplier relationships
- A.16 Information security incident management
- A.17 Information security aspects of business continuity management
- A.18 Compliance
ISO 27001 requirements
- 4.1 Understanding the organisation and its context
- 4.2 Understanding the needs and expectations of interested parties
- 4.3 Determining the scope of the information security management system
- 4.4 Information security management system
- 5.1 Leadership and commitment
- 5.2 Information Security Policy
- 5.3 Organizational roles, responsibilities and authorities
- 6.1 Actions to address risks and opportunities
- 6.2 Information security objectives and planning to achieve them
- 7.1 Resources
- 7.2 Competence
- 7.3 Awareness
- 7.4 Communication
- 7.5 Documented information
- 8.1 Operational planning and control
- 8.2 Information security risk assessment
- 8.3 Information security risk treatment
- 9.1 Monitoring, measurement, analysis and evaluation
- 9.2 Internal audit
- 9.3 Management review
- 10.1 Nonconformity and corrective action
- 10.2 Continual improvement