10.2 Nonconformities and Corrective Action
To satisfy ISO/IEC 27001 Clause 10.2, anDREa maintains a structured process to react to, investigate, and remediate nonconformities. We ensure that any systemic breakdown, audit failure, or operational deviation is contained, evaluated for root causes, and permanently corrected to prevent recurrence.
10.2.1 The Nonconformity and Corrective Action Lifecycle
When a security or compliance nonconformity is identified—whether through internal monitoring, automated metrics, or external audits—anDREa executes the following lifecycle:
1. Registration and Containment
The finding is immediately logged as a high-priority ticket within our internal tracking system. The asset owner takes immediate containment actions to control the deviation and mitigate any near-term consequences or security risks.
2. Root Cause Analysis (RCA)
The Director or designated security engineer conducts an objective investigation within the ticket to identify why the breakdown occurred. This process requires:
- Reviewing the mechanics of the specific failure.
- Determining the underlying technical, operational, or behavioral root causes.
- Scanning the broader myDRE ecosystem to determine if similar nonconformities exist or could potentially occur elsewhere.
3. Corrective Action Plan (CAP) Development
Based on the root cause analysis, a formal Corrective Action Plan (CAP) is designed. The CAP outlines specific long-term remediation steps, architectural changes, or policy updates required to eliminate the root cause, along with a clear deadline for implementation.
4. Governance Review and Verification
- Management Approval: The Management Team must formally review and confirm that both the root cause analysis and the proposed CAP are adequate before any long-term engineering or process changes begin.
- Effectiveness Review: Once the CAP is deployed, the Information Security Management Board (ISMB) monitors the control over a defined testing window to verify that the corrective actions have successfully eliminated the vulnerability without introducing regressions.
- Ticket Closure: A nonconformity ticket is officially closed only after top management reviews the operational evidence and explicitly signs off on its completion.
10.2.2 Information Preservation and Registries
anDREa retains comprehensive, documented evidence of the nature of all discovered nonconformities, subsequent containment steps, authorized CAP formulations, and final execution results.
Access to this data is managed through strict role-based IAM policies across our operational environments:
1. Restricted Compliance Registries (Authorized Personnel Only)
Due to the presence of internal system vulnerability data, these assets are restricted to authenticated security and management personnel:
- Nonconformity Tracking Tickets: Active and historical engineering entries detailing localized process failures and containment steps.
- Corrective Action Plans (CAPs): Explicit technical blueprints and remediation roadmaps linked directly to tracking tickets.
- Internal and External Audit Reports: Complete audit lifecycles and formal third-party compliance reviews detailing identified gaps (Clause 9.2).
- ISMB Action Registry: Historical governance board records tracking the remediation progress of open organizational findings.
- Bi-Annual Security Items Review: Periodic leadership evaluations assessing long-term trend data for unresolved exceptions or systemic weaknesses.
2. Public Security Metrics
- Security Effectiveness Metrics: High-level, aggregated trend telemetry demonstrating the overall performance and health of the myDRE platform's control environment (see Information Security Performance).
- Executive Transparency: The Director distills the final audit report into an internal management summary for publication in Management Reports.