Information Security Management

ISO 27001 Continual Improvement Phase

In my fifth and final guide in the series on how to implement ISO 27001, I look at continual improvement, which naturally aligns with Clause 10: Improvement within ISO 27001.

Continual improvement is essential for achieving and maintaining ISO 27001 certification, as it demonstrates your organisation’s commitment to ongoing information security and compliance.

Here we’ll look at how you can meet the requirement to reflect on your ISMS performance and make changes to push the performance on to greater heights and delight your auditor each time they review it.

Without improvement, your ISMS will roll backwards, losing the momentum and maturity you have worked hard to build.

Includes all the mandatory document templates — free, no commitment

Written by Alan Parker – ISO 27001 Consultant
the iso 27001 continuous improvement phase

ISO 27001 Monitoring & Review Phase Overview

< Back to the Monitoring & Review Phase of the project

Don’t worry, my friend, we’ve almost made it.

The Continual Improvement phase of ISO 27001 implementation focuses on maintaining and enhancing the effectiveness of the Information Security Management System (ISMS). In this implementation plan, it is directly linked to Clause 10 “Improvement”. Effective management systems play a key role in supporting continual improvement by providing the structure needed for ongoing evaluation and enhancement.

A diagram depicting the steps in the continuous improvement stage of an ISO 27001 project
The Continual Improvement Phase of ISO 27001

This phase ensures the ISMS evolves with the organisation’s changing needs and continually improves its information security posture.

Through systematic review and improvement activities, including process reviews and enhancements, this phase helps address nonconformities, implement corrective actions, and foster a culture of continuous improvement.

In the previous stage, I talked about the Plan-Do-Check-Act cycle. Well, this part is the “Act”.

The inputs are numerous, but include;

  • ISMS Performance Report
  • Management Review Minutes
  • Audit Findings
  • Nonconformities Log
  • Risk Assessments (if they identify improvement ideas)

These input into the step: Create an Improvement Plan

And output… guess what? An improvement plan.

Each step is crucial in ensuring a comprehensive and systematic implementation of an Information Security Management System (ISMS). Let’s take a look at each one in turn.

Everything I discuss here is based on the utilisation of my toolkit and the templates therein, so I encourage you to download my ISO 27001 toolkit and use that as the basis of your ISMS’ foundations.

ISO 27001 Online Course + Full Toolkit

Stop guessing. Follow a proven step-by-step process.

Highly recommended for anyone looking to understand ISO 27001, whether attempting it on your own or even using a consultant.

iso 27001 course screenshot

£285

Instant access

View Details Try the demo →

Includes full document toolkit · 30-day consultancy upgrade credit

✓ Full toolkit included ✓ Learn as you build ✓ 12-month access ✓ 6 hours of video ✓ Email consultancy


The primary purpose of the Continual Improvement phase is to develop a comprehensive improvement plan.

The improvement plan is based on inputs from ISMS performance reports, management review minutes, audit findings, and non-conformities log. It aims to address identified nonconformities and propose actions to enhance the Information Security Management System (ISMS). As part of this process, it is important to identify opportunities for improvement by systematically reviewing these inputs.

Having an Improvement Plan is not mandatory, but you do have to demonstrate how you are taking the outputs from the previous stage “Monitoring & Review” and then acting upon non-conformances and deviations. When prioritising issues, you should evaluate the potential benefits of each improvement. A risk-based approach should be used to determine which actions to prioritise in the improvement plan.

Activities

Collect Inputs

There are lots of sources of improvement inputs, but here are the main ones;

Gather data from regular monitoring and measurement activities. This includes metrics on incident response times, the number of security breaches, compliance levels, and other key performance indicators you identified as important in the previous stage.

Use performance reports to identify trends, deviations, and areas for improvement.

Utilise minutes from the management review meetings (ISG). These minutes provide insights into the ISMS’s overall performance, highlight strategic areas for improvement, and record decisions made by senior management.

Leverage findings from internal audits and external audits. Internal audit is a mandatory, structured process under ISO 27001 for assessing the ISMS, identifying nonconformities, and supporting continual improvement. Audit reports should highlight non-conformities, observations, and recommendations for improvement. They are an absolute wealth of ideas for improvement.

Maintain a log of all identified non-conformities from various sources, including audits, incident reports, and monitoring activities. Security incidents (when things haven’t gone to plan or retrospectives identify areas for improvement) should also be tracked in this log, as they are a primary source for identifying nonconformities and driving improvement actions.

Ensure you track the status of each non-conformity, including the root cause analysis, corrective actions taken, and verification of their effectiveness.

Identify Non-Conformities and Areas for Improvement

Review the collected inputs to identify any nonconformities, weaknesses, or areas for improvement, as well as vulnerabilities in the ISMS.

Prioritise the identified issues based on their impact on the ISMS and organisational objectives, and identify areas for enhancement.

Identifying opportunities for improvement is a crucial part of this process.

Develop Actionable Plans

Formulate specific, measurable, achievable, relevant, and time-bound (SMART) actions to address the identified non-conformities and areas for improvement.

Assign responsibilities for each action item to ensure accountability and effective implementation. Ensure that teams are prepared to implement improvements as part of their assigned duties.

Set realistic timelines for completing each action item and ensure that resources are available to support the implementation. Track progress and verify that implemented improvements achieve their intended goals.

Effective change management is essential throughout this process to ensure that improvements are successfully integrated and sustained.

Document the Improvement Plan

Create a detailed improvement plan document that outlines the identified issues, proposed actions, the controls designed to address them, responsible parties, and timelines. Documentation of the improvement plan is a key part of the continual improvement process, ensuring that all steps are tracked and managed effectively.

Ensure that the improvement plan is reviewed and approved by senior management to ensure alignment with organisational goals and resource commitment.

Monitor and Review Implementation:

Given that the entire stage is about reviewing progress and acting upon it, we will need to track the improvements and their progress by defining metrics and monitoring systems to track the progress of improvement actions.

Continuously monitor the progress of improvement actions to ensure they are implemented as planned and verify that the actions achieve their intended outcomes.

Conduct regular reviews to assess the effectiveness of the actions taken, ensure the ISMS remains effective, and make necessary adjustments based on feedback and performance data.


 

As mentioned earlier, Clause 10 of ISO 27001:2022 focuses on continual improvement of the Information Security Management System (ISMS). Organisations are required to continually improve the ISMS to ensure its ongoing effectiveness, suitability, and adequacy.

This clause mandates organisations to enhance the effectiveness of the ISMS through continuous review and improvement activities, with a focus on continually improving their information security posture.

To implement continual improvement as required by Clause 10, organisations should take practical steps, such as identifying opportunities for improvement, implementing corrective actions, and regularly reviewing performance. These continual improvement efforts are essential for systematically reviewing and enhancing the ISMS to maintain compliance and effectiveness.

The Continual Improvement phase of the implementation supports Clause 10 by systematically addressing nonconformities, implementing corrective actions, and promoting ongoing enhancements to the ISMS, thereby ensuring the organisation continually improves its management system.

Continual Improvement (Clause 10.1)

The Continual Improvement phase ensures the ISMS evolves with the organisation’s changing needs and continuously improves its information security posture. Top management plays a critical role in supporting and engaging with continual improvement efforts, ensuring alignment with business objectives and the organisation’s overall strategy. Everyone’s responsibility is essential in maintaining and improving the ISMS, as effective information security relies on the active participation of all staff and relevant interested parties.

  • Created, Documented & Communicated an Improvement Plan – We’ve developed a comprehensive improvement plan based on inputs from performance reports, management reviews, audit findings, non-conformities log , and identified opportunities for improvement (OFIs).. Then, we’ve documented the improvement plan detailing identified issues, proposed actions, responsible parties, and timelines. We communicated the plan to all relevant stakeholders, involving staff and interested parties in the process, and ensuring that other interested parties are kept informed of progress and positive changes.
  • Monitor and Review Implementation – Continuously monitor the progress of improvement actions to ensure effective implementation and ongoing effectiveness. Regularly review the actions taken to assess their effectiveness, gather valuable insights from staff and stakeholders, and make necessary adjustments. Providing training and implementing training programs support staff and stakeholders in improvement activities, helping to make positive changes and achieve business objectives. Involving staff in the process and acting on valuable insights ensures continual improvement is embedded throughout the organisation.

Nonconformity & Corrective Action (Clause 10.2)

The Continual Improvement phase ensures the ISMS evolves with the organisation’s changing needs and continuously improves its information security posture.

  • Collected Inputs – Regularly gather data from ISMS performance reports, management review minutes, audit findings, and non-conformities log to identify issues and recognised opportunities for improvement.
  • Identified Non-Conformities – Reviewed inputs to detect non-conformities, weaknesses, or areas needing improvement, including identified opportunities and OFIs (Opportunities for Improvement).
  • Developed Corrective Actions – We have formulated specific actions to address the identified non-conformities following a documented corrective action process. Actions are designed to prevent recurrence of nonconformities and are planned with consideration of applicable regulatory requirements.
  • Monitor and Review Implementation – We will continuously monitor the progress of improvement actions to ensure effective implementation. Implemented improvements are reviewed to verify they address the identified opportunities and achieve their intended outcomes.