Skip to content

Corrective Action Procedure

This procedure defines how Cadence OneFive identifies, documents, and resolves nonconformities within the ISMS, in accordance with ISO 27001:2022 clause 10.2.

This procedure applies to all nonconformities identified through any source, including:

  • Internal or external audits
  • Security incidents
  • Metric analysis (e.g., missed SLAs, failed objectives)
  • Management review findings
  • Employee or stakeholder feedback
  • Operational observations

When a nonconformity is identified, the CISO (or the person who identified it) takes immediate action to:

  • Control and correct the nonconformity to limit its impact
  • Deal with the consequences (e.g., notify affected parties, restore service, contain a breach)

Before determining corrective action, the nonconformity is evaluated to understand its cause and scope:

  • Review the nonconformity — Understand what happened, when, and what was affected
  • Determine root cause — Identify why the nonconformity occurred (not just the symptoms)
  • Assess scope — Determine if similar nonconformities exist elsewhere, or could potentially occur

Based on the root cause analysis, corrective action is implemented to eliminate the cause so the nonconformity does not recur. Corrective actions must be proportionate to the effects of the nonconformity.

After corrective action is implemented, its effectiveness is verified. If the nonconformity recurs or the corrective action is insufficient, the process repeats from the root cause evaluation step.

If the corrective action reveals a need for changes to policies, procedures, controls, or the risk assessment, those changes are made through the standard change process (pull request to the handbook or update to the relevant record).

Nonconformities and corrective actions are tracked as issues on the Policy section of the DevOps & Security GitHub project board. Each issue documents:

Field Description
Description Nature of the nonconformity and what was affected
Source How the nonconformity was identified (audit, incident, metric, review, etc.)
Root Cause Why the nonconformity occurred
Corrective Action Action taken to eliminate the root cause
Responsible Person Who is responsible for implementing the corrective action
Target Date Deadline for completion
Effectiveness Review Verification that the corrective action worked

This documented information satisfies ISO 27001:2022 clause 10.2 requirements for evidence of the nature of nonconformities, subsequent actions taken, and the results of corrective action.

Audit findings that result in nonconformities are classified as:

Classification Definition
Major nonconformity Absence or complete failure of a required control
Minor nonconformity Partial implementation or isolated failure of a control
Observation Opportunity for improvement, not a nonconformity

Major nonconformities are escalated to the Head of Platform and prioritized for immediate corrective action.

Role Responsibility
Head of Platform Accountable for ensuring corrective actions are completed; reviews major nonconformities
CISO Maintains the nonconformity log; coordinates root cause analysis; verifies corrective action effectiveness; reports status quarterly and during management review
Responsible Person Implements assigned corrective actions within the target date
All Personnel Report potential nonconformities to the CISO via Discord #tech_security

The CISO reviews open corrective actions quarterly and reports status during management review per ISMS Manual §9.3.

  • ISMS Manual — Governance framework, including continual improvement (§10.1) and management review (§9.3)
  • Business Continuity and Disaster Recovery — Incident response procedures that may surface nonconformities
  • Incident Response Plan — Operational incident handling; security incidents resolved through this plan may surface nonconformities that feed into the corrective action process
  • This procedure will be reviewed annually and updated as necessary to reflect changes in the ISMS or organizational context.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.