Case study 2 – reporting NCs
Reporting NCs during an audit is essential, as it enables organizations to identify and document deviations from established information security controls. It also provides valuable insights into areas that require corrective actions and improvements to maintain the integrity and effectiveness of their information security management system.
Major versus minor NC and OFIs
A major NC is a significant deviation or lapse in a system or process that either has led, or may potentially lead, to a failure to fulfil a requirement specified by a standard or regulation. This can include situations where a large part or all of a required system is either not implemented or ineffectively managed. Major NCs typically require immediate corrective action due to their severity, and they may significantly impact the quality, safety, or efficacy of the product or service, or pose a serious risk to the business or its customers.
An example of a major NC is...