5.2 The PDCA Cycle Applied to the ISMS

Key Takeaways

  • PDCA maps to ISO/IEC 27001 clauses in order: Plan = Clauses 4–6, Do = Clauses 7–8, Check = Clause 9, Act = Clause 10.
  • The Statement of Applicability (SoA) is a Plan-phase deliverable (Clause 6.1.3), even though its controls are implemented in the Do phase (Clause 8).
  • Check (Clause 9) separates internal audit (9.2, performed by auditors) from management review (9.3, performed by top management).
  • Act (Clause 10) separates continual improvement (10.1, opportunity-driven) from corrective action (10.2, nonconformity-driven).
  • Awareness (Clause 7.3) applies to everyone in scope, not just security staff — a common exam distractor.
Last updated: July 2026

The PDCA Cycle

Plan-Do-Check-Act (PDCA) is the quality-improvement model originated by Walter Shewhart and popularized by W. Edwards Deming. ISO/IEC 27001:2022 explicitly aligns its clause structure to PDCA so that the standard reads as a continual-improvement loop rather than a static checklist.

For the ISMS, PDCA maps cleanly to the clause numbers:

PDCA PhaseISO/IEC 27001 ClausesWhat happens
PlanClauses 4, 5, 6Establish the ISMS: context, leadership, planning, risk assessment, objectives, SoA.
DoClauses 7, 8Implement and operate: support (resources, competence, awareness, communication, documented information) and operation (risk treatment, control implementation).
CheckClause 9Monitor, measure, analyze, internal audit, management review.
ActClause 10Improve: nonconformity and corrective action, continual improvement.

The numbering itself is a memory aid: clauses ascend through PDCA in order. Memorize the four boundary points (4, 7, 9, 10) and you can derive any clause's phase.

Plan — Establish the ISMS (Clauses 4–6)

The Plan phase answers the question, "What are we trying to secure, why, and how?"

  • Clause 4 (Context of the organization): Determine internal and external issues (4.1), interested parties and their requirements (4.2), and the ISMS scope (4.3). Clause 4.4 requires the organization to establish, implement, maintain, and continually improve the ISMS.
  • Clause 5 (Leadership): Top management must demonstrate leadership and commitment (5.1), establish an information security policy (5.2), and assign roles, responsibilities, and authorities (5.3).
  • Clause 6 (Planning): Plan actions to address risks and opportunities (6.1), including the information security risk assessment process and risk treatment. Set measurable information security objectives (6.2) and plans to achieve them. Clause 6.1.3 requires producing the Statement of Applicability (SoA) — the bridge from Plan to Do.

The output of Plan is a documented ISMS design: scope, policy, risk assessment, risk treatment plan, objectives, and SoA. Without these, the Do phase has nothing to implement.

Do — Implement and Operate (Clauses 7–8)

The Do phase answers, "Are we doing what we planned?"

  • Clause 7 (Support): Provide resources (7.1), ensure competence (7.2), build awareness (7.3), manage internal and external communication (7.4), and control documented information (7.5).
  • Clause 8 (Operation): Plan and control operational processes (8.1), perform the information security risk assessment at planned intervals and on significant changes (8.2), and implement the risk treatment plan (8.3) with evidence that controls operate as intended.

Awareness (7.3) is a frequent exam target — every employee in scope, not just security staff, must understand the information security policy, their contribution to the ISMS, and the implications of not conforming.

Check — Monitor and Review (Clause 9)

The Check phase answers, "Is our ISMS working, and how do we know?"

  • Clause 9.1 (Monitoring, measurement, analysis, and evaluation): Determine what needs to be measured, when, by whom, and what the results mean.
  • Clause 9.2 (Internal audit): Conduct audits at planned intervals that are objective, impartial, and report results to management. Auditors must be independent of the activity being audited.
  • Clause 9.3 (Management review): Top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.

A common distractor confuses internal audit (Clause 9.2) with management review (Clause 9.3). Internal audit is performed by auditors; management review is performed by top management. They are distinct inputs to continual improvement.

Act — Improve (Clause 10)

The Act phase answers, "What will we change to make the ISMS better?"

  • Clause 10.1 (Continual improvement): Continually improve the suitability, adequacy, and effectiveness of the ISMS.
  • Clause 10.2 (Nonconformity and corrective action): React to nonconformities, evaluate the need for corrective action to eliminate root causes, implement the actions needed, review their effectiveness, and update risks and opportunities. Documented information must be available as evidence of corrective action results.

Note the order: a nonconformity triggers corrective action (root-cause based), which is distinct from continual improvement (opportunity-driven). The exam sometimes swaps the two — read carefully.

Exam Traps and Scenarios

  • Trap 1: A question places Clause 9 in "Act." Correct: Clause 9 is Check; Clause 10 is Act.
  • Trap 2: A question assigns the SoA to the Do phase. Correct: the SoA is produced in Clause 6.1.3 (Plan), even though controls are implemented in Clause 8 (Do).
  • Trap 3: A question treats Clause 7 (Support) as part of Plan. Correct: Support is Do — it operationalizes what Plan designed.
  • Trap 4: A question puts internal audit in Act. Correct: internal audit is Check (9.2); the response to audit findings (corrective action) is Act (10.2).
  • Trap 5: A question labels "continual improvement" as corrective action. Correct: continual improvement (10.1) is opportunity-driven; corrective action (10.2) is nonconformity-driven.
Loading diagram...
PDCA Cycle Mapped to ISO/IEC 27001:2022 Clauses
Test Your Knowledge

Under the PDCA mapping in ISO/IEC 27001:2022, which clauses belong to the Do phase?

A
B
C
D
Test Your Knowledge

Where does the Statement of Applicability (SoA) sit in the PDCA cycle?

A
B
C
D
Test Your Knowledge

What is the correct distinction between Clause 9.2 (Internal audit) and Clause 9.3 (Management review)?

A
B
C
D