Looking at the strategies for continual improvement
To evaluate, test, review, and measure the success of the ISMS as a component of a larger business-led strategy, organizations that take improvement seriously need to conduct assessments, tests, and reviews.
Clause 10 of ISO 27001 requires an organization to “continually improve the suitability, adequacy and effectiveness of the information security management system” (https://www.iso.org/). Documenting your continual improvement process is the most efficient approach to fulfilling this responsibility and complying with its requirements.
According to PDCA, each process that is carried out as a part of the management system needs to be planned, carried out, monitored, and improved. This method is an integral part of the standard and contributes to the continual improvement of ISMS (Figure 10.1). Continual improvement is the product of several procedures that make up the ISMS. The ISO/IEC 27001 standard details the...