6.7 Clause 10: Improvement
Key Takeaways
- Clause 10 corresponds to the 'Act' phase of PDCA, closing the loop through continual improvement (10.1) and nonconformity and corrective action (10.2)
- A correction fixes the symptom; corrective action eliminates the root cause and prevents recurrence elsewhere — the distinction is heavily tested
- Clause 10.2 requires reviewing the effectiveness of corrective action — implementation alone is not sufficient
- Clause 10.1 continually improves suitability, adequacy, and effectiveness — the same three keywords used in Clause 9.3 management review
- Root cause analysis is mandatory under 10.2; common techniques include 5 Whys, fishbone (Ishikawa) diagrams, and fault tree analysis
Clause 10 is the "Act" phase of PDCA. It closes the loop by requiring the organization to continually improve the ISMS and to respond to nonconformities through corrective action. Without Clause 10, the ISMS is static — risks change, controls degrade, and lessons learned never feed back into the system.
10.1 Continual Improvement
The organization must continually improve the suitability, adequacy, and effectiveness of the ISMS. The three keywords are the same as those used in management review (9.3) and are not interchangeable:
- Suitability — does the ISMS still fit the organization's context, scope, and risk landscape?
- Adequacy — is the ISMS sufficient to address the organization's risks and objectives?
- Effectiveness — is the ISMS actually achieving its intended outcomes and information security objectives?
Continual improvement draws on inputs from Clause 9: management review outputs, audit results, monitoring data, and stakeholder feedback. Improvement may be incremental (small day-to-day adjustments) or breakthrough (major redesigns of processes or controls). ISO/IEC 27001 does not require a specific improvement methodology — Plan-Do-Check-Act, Six Sigma DMAIC, or Kaizen may all be applied.
A common trap: the Foundation exam sometimes pairs the three keywords with the CIA triad (confidentiality, integrity, availability). The CIA triad is an information security principles concept, not the wording of Clause 10.1.
10.2 Nonconformity and Corrective Action
A nonconformity is the non-fulfilment of a requirement. It may be detected through audits (internal or external), monitoring, management review, incident reports, or stakeholder complaints. When a nonconformity arises, the organization must:
- React to the nonconformity and, as applicable:
- Take action to control and correct it
- Deal with the consequences
- Evaluate the need for action to eliminate the causes of the nonconformity, so that it does not recur or occur elsewhere, by:
- Reviewing and analyzing the nonconformity
- Determining the causes of the nonconformity (root cause analysis)
- Determining if similar nonconformities exist, or could potentially occur
- Implement any action needed
- Review the effectiveness of any corrective action taken
- Make changes to the ISMS, if necessary
The organization must retain documented information as evidence of:
- The nature of the nonconformities and any subsequent actions taken
- The results of any corrective action
Correction vs Corrective Action
This is the most heavily tested distinction in Clause 10:
| Term | Definition | Example |
|---|---|---|
| Correction | Immediate action to fix the symptom | Patch a misconfigured server |
| Corrective action | Action to eliminate the root cause so the nonconformity does not recur | Update the change management procedure and retrain staff |
A correction is part of step 1 ("react"); corrective action is the broader root-cause-driven process. The exam may present a scenario where only the symptom is fixed and ask whether corrective action was taken — the answer is no, because the root cause was not addressed.
Root Cause Analysis Techniques
Step 2 of Clause 10.2 requires determining the causes of the nonconformity. Common techniques include:
- 5 Whys — iterative questioning to surface root cause
- Fishbone (Ishikawa) diagram — categorizes causes (people, process, technology, environment)
- Fault tree analysis — top-down deductive analysis of failure paths
- Pareto analysis — identifies the most significant contributing factors
The Foundation exam typically does not require detailed knowledge of these techniques, but may test that root cause analysis is required (not optional) and that the goal is to prevent recurrence.
"Does Not Recur or Occur Elsewhere"
A subtle but exam-relevant point: corrective action must prevent the nonconformity from recurring AND from occurring elsewhere. If a missing patch is found on one server, the corrective action should check whether other servers have the same gap — not just fix the one server. This "occur elsewhere" language is unique to management system standards and is frequently tested.
Effectiveness Review Is Mandatory
Step 4 requires the organization to review the effectiveness of any corrective action taken. Implementing an action is not enough — the organization must verify that the action actually eliminated the root cause and prevented recurrence. This is typically done through follow-up audits, monitoring data, or trend analysis.
PDCA Act Phase Mapping
| PDCA Phase | Clause 10 Element |
|---|---|
| Act | 10.1 Continual improvement |
| Act | 10.2 Nonconformity and corrective action |
Clause 10 closes the PDCA loop by feeding lessons learned back into Clauses 4-9. A mature ISMS treats every nonconformity as an improvement opportunity, not merely a problem to be patched.
Common Traps
- Correction ≠ corrective action. Patching a server is a correction; eliminating the root cause is corrective action.
- Review effectiveness is mandatory. Step 4 requires verification that the corrective action worked — implementing an action is not enough.
- Prevention extends to "elsewhere." Corrective action must consider whether the same nonconformity could occur in other areas, processes, or systems.
- The three keywords are suitability, adequacy, effectiveness — not confidentiality, integrity, availability.
An ISMS auditor finds that an employee's access rights were not removed after termination. HR immediately disables the account. What additional step is required by Clause 10.2?
Which sequence correctly reflects the order of Clause 10.2 requirements following the detection of a nonconformity?
Clause 10.1 requires the organization to continually improve which three attributes of the ISMS?