Corrective Action Procedure
Purpose
Section titled “Purpose”This procedure defines how Cadence OneFive identifies, documents, and resolves nonconformities within the ISMS, in accordance with ISO 27001:2022 clause 10.2.
This procedure applies to all nonconformities identified through any source, including:
- Internal or external audits
- Security incidents
- Metric analysis (e.g., missed SLAs, failed objectives)
- Management review findings
- Employee or stakeholder feedback
- Operational observations
Corrective Action Process
Section titled “Corrective Action Process”React to the Nonconformity
Section titled “React to the Nonconformity”When a nonconformity is identified, the CISO (or the person who identified it) takes immediate action to:
- Control and correct the nonconformity to limit its impact
- Deal with the consequences (e.g., notify affected parties, restore service, contain a breach)
Evaluate Root Cause
Section titled “Evaluate Root Cause”Before determining corrective action, the nonconformity is evaluated to understand its cause and scope:
- Review the nonconformity — Understand what happened, when, and what was affected
- Determine root cause — Identify why the nonconformity occurred (not just the symptoms)
- Assess scope — Determine if similar nonconformities exist elsewhere, or could potentially occur
Implement Corrective Action
Section titled “Implement Corrective Action”Based on the root cause analysis, corrective action is implemented to eliminate the cause so the nonconformity does not recur. Corrective actions must be proportionate to the effects of the nonconformity.
Review Effectiveness
Section titled “Review Effectiveness”After corrective action is implemented, its effectiveness is verified. If the nonconformity recurs or the corrective action is insufficient, the process repeats from the root cause evaluation step.
Update the ISMS
Section titled “Update the ISMS”If the corrective action reveals a need for changes to policies, procedures, controls, or the risk assessment, those changes are made through the standard change process (pull request to the handbook or update to the relevant record).
Tracking
Section titled “Tracking”Nonconformities and corrective actions are tracked as issues on the Policy section of the DevOps & Security GitHub project board. Each issue documents:
| Field | Description |
|---|---|
| Description | Nature of the nonconformity and what was affected |
| Source | How the nonconformity was identified (audit, incident, metric, review, etc.) |
| Root Cause | Why the nonconformity occurred |
| Corrective Action | Action taken to eliminate the root cause |
| Responsible Person | Who is responsible for implementing the corrective action |
| Target Date | Deadline for completion |
| Effectiveness Review | Verification that the corrective action worked |
This documented information satisfies ISO 27001:2022 clause 10.2 requirements for evidence of the nature of nonconformities, subsequent actions taken, and the results of corrective action.
Classification
Section titled “Classification”Audit findings that result in nonconformities are classified as:
| Classification | Definition |
|---|---|
| Major nonconformity | Absence or complete failure of a required control |
| Minor nonconformity | Partial implementation or isolated failure of a control |
| Observation | Opportunity for improvement, not a nonconformity |
Major nonconformities are escalated to the Head of Platform and prioritized for immediate corrective action.
Roles and Responsibilities
Section titled “Roles and Responsibilities”| Role | Responsibility |
|---|---|
| Head of Platform | Accountable for ensuring corrective actions are completed; reviews major nonconformities |
| CISO | Maintains the nonconformity log; coordinates root cause analysis; verifies corrective action effectiveness; reports status quarterly and during management review |
| Responsible Person | Implements assigned corrective actions within the target date |
| All Personnel | Report potential nonconformities to the CISO via Discord #tech_security |
Review Cycle
Section titled “Review Cycle”The CISO reviews open corrective actions quarterly and reports status during management review per ISMS Manual §9.3.
Related Documents
Section titled “Related Documents”- ISMS Manual — Governance framework, including continual improvement (§10.1) and management review (§9.3)
- Business Continuity and Disaster Recovery — Incident response procedures that may surface nonconformities
- Incident Response Plan — Operational incident handling; security incidents resolved through this plan may surface nonconformities that feed into the corrective action process
Policy Review
Section titled “Policy Review”- This procedure will be reviewed annually and updated as necessary to reflect changes in the ISMS or organizational context.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
