4. Incidents, audits and improvement
Corrective action, continual improvement, and your part
ISO 27001 does not expect perfection. It expects a system that notices its own failures and gets better. That expectation has some specific machinery behind it.
Corrective action
When a nonconformity is found, through an audit, an incident, or someone speaking up, the organisation must react to it, deal with the consequences, and then look deeper: why did this happen, and could it happen elsewhere? Fixing the root cause is what makes a corrective action different from a quick patch. If a leaver kept system access for three months, resetting that one account is the patch. Fixing the leaver process so access is always removed on the last day is the corrective action. The standard requires the deeper fix, and requires the organisation to check later that it actually worked.
Continual improvement
The whole ISMS runs on a repeating cycle: plan what is needed, do it, check whether it is working, and act on what the checks reveal. Risk assessments are refreshed as the organisation changes, controls are adjusted, policies are updated, and lessons from incidents and audits are folded back in. This is why you will see policies revised and training repeated. It is not churn, it is the standard working as designed. Security that stands still falls behind, because the threats do not stand still.
Management review
At planned intervals, top management formally reviews the ISMS: incident trends, audit results, progress on corrective actions, whether objectives are being met, and what needs to change. This keeps security decisions where the standard insists they belong, with leadership, and keeps resources flowing to the problems that matter.
Your part in keeping certification
Certification is renewed through evidence, and most of that evidence is generated by ordinary people doing ordinary things well. Follow the policies for your role. Lock your screen, clear your desk, protect your credentials. Classify and handle information properly. Report events, weaknesses, and mistakes promptly, including your own. Answer auditors honestly. Raise the rules that do not work instead of quietly ignoring them.
None of that requires technical expertise. All of it is what an ISMS looks like from the inside, and it is the reason the certificate on the website is worth the paper it is printed on.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement
Putting it into practice