Performance Evaluation & Improvement (Clauses 9-10)
Learn what clause 9 requires for monitoring, internal audit, and management review, and how clause 10 turns findings into corrective action that closes the PDCA loop back to clause 6.
Learning Objectives
- → List what clause 9.1 requires an organization to monitor and measure
- → Explain the independence requirement for internal audits
- → Name the required inputs and outputs of a management review
- → Distinguish a nonconformity from its root cause, and correction from corrective action
Clauses 9 and 10 are the "Check" and "Act" of the PDCA cycle from lesson 1. This is where an ISMS proves it isn't just a one-time paperwork exercise — it's the mechanism that catches drift and pushes fixes back into the system.
9.1: Monitoring, measurement, analysis and evaluation
Clause 9.1 requires the organization to determine: what needs to be monitored and measured, the methods for doing so (to ensure valid, comparable results), when monitoring happens, who does it, when results are analyzed, and who analyzes them. This is deliberately broader than just the clause 6.2 objectives — it also covers whether controls themselves are working as intended.
A common mistake: treating this as "we'll look into it if something goes wrong." Clause 9.1 expects planned, proactive measurement — for example, tracking the percentage of critical vulnerabilities patched within SLA, or the number of failed login attempts trending over time — not purely reactive investigation after an incident.
9.2: Internal audit
Every certified organization must conduct internal audits at planned intervals to check whether the ISMS conforms to both the organization's own requirements and the standard's requirements, and whether it's effectively implemented and maintained.
The single most tested Foundation-level detail here is independence: auditors must not audit their own work. A security engineer who configured a firewall rule cannot be the one who audits whether that firewall rule is appropriate — this doesn't require an external auditor (internal audits can be done by trained internal staff), but it does require someone sufficiently removed from the process being audited. In a very small organization, this sometimes means bringing in an external contractor for internal audits, precisely because there's no one else internally independent enough.
9.3: Management review
Top management must review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. The standard specifies required inputs (what must be discussed) and expects concrete outputs:
| Required inputs (examples) | Expected outputs |
|---|---|
| Status of actions from previous reviews | Decisions on improvement opportunities |
| Changes in external/internal issues (clause 4.1) | Decisions on ISMS changes |
| Nonconformities and corrective actions | Resource needs identified |
| Monitoring and measurement results | — |
| Audit results | — |
| Achievement of security objectives | — |
A management review that's just a 10-minute rubber stamp with no real discussion of these inputs — and no decisions coming out the other side — is a weak spot auditors specifically probe, connecting back to the leadership commitment concerns from clause 5.
10.1 & 10.2: Continual improvement and nonconformity/corrective action
Clause 10.2 requires that when a nonconformity occurs (something not meeting a requirement — either the standard's or the organization's own), the organization must:
- React to it — take action to control and correct it, and deal with the consequences
- Evaluate whether similar nonconformities exist or could occur elsewhere
- Determine the root cause
- Determine if similar nonconformities exist elsewhere
- Implement any action needed
- Review the effectiveness of the corrective action taken
- Make changes to the ISMS if necessary
A critical distinction: correction fixes the immediate instance (e.g., revoking one ex-employee's still-active account that should have been disabled). Corrective action addresses the root cause so it doesn't recur (e.g., fixing the offboarding process so accounts are automatically disabled on the employee's last day). Fixing only the immediate instance, without addressing why it happened, is a classic finding — the same nonconformity tends to resurface elsewhere in the organization.
This is the clause where the PDCA cycle from lesson 1 becomes concrete: findings from 9.1/9.2/9.3 feed clause 10's corrective action process, and lessons learned feed back into clause 6 risk assessment for the next cycle.
A three-person IT team includes one person who manages the company's firewall configuration full-time. The company assigns that same person to conduct the internal audit of network security controls, since 'they know the firewall best.' Explain why this violates the clause 9.2 independence requirement, and propose a fix appropriate for a very small organization.
Why can't the firewall administrator audit the firewall controls they themselves manage?
An ex-employee's account was found still active three weeks after their last day. The IT team immediately disables the account (same day the issue is found). Two months later, another ex-employee's account is found still active. Explain what went wrong from a clause 10.2 perspective.
What clause 10.2 step was most likely skipped after the first incident, given that the same problem recurred?
List at least 5 required inputs for a management review, based on the lesson content, and for each, state what would happen if it were silently skipped from the meeting agenda.
If 'status of actions from previous management reviews' is silently dropped from the agenda every time, what practical risk does this create?
💪 Exercises & Challenges
Evaluation & Improvement — MCQ
Evaluation & Improvement — MCQ
Draft a Management Review Agenda
Draft a Management Review Agenda
Correction, Corrective Action, or Neither?
Correction, Corrective Action, or Neither?