Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-21_Nichtkonformitaeten-und-Korrekturmassnahmen.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

3.9 KiB

Nonconformities & Corrective Actions

Document information Value
Document type Procedure instruction (VA-21)
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Process owner {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This procedure governs the recording, root cause analysis, treatment and effectiveness review of nonconformities and the continual improvement of the ISMS derived from them. It elaborates the corresponding policy ({{LINK:R03}}).

The procedure also carries the requirement to correct and follow up deviations, as required by the compliance review in security operations ({{LINK:VA-15}}) — it therefore applies regardless of which framework the organisation follows.

2. Scope

Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) to all nonconformities against policies, procedures, technical requirements as well as legal and contractual obligations.

3. Trigger

Audit finding, result of a compliance review, security incident, deviation of a metric from its target value, report from operations or third parties, observation during the management review.

4. Inputs

  • Audit reports and findings ({{LINK:VA-15}})
  • Incidents and lessons learned ({{LINK:VA-01}})
  • Metrics deviating from their target value ({{LINK:VA-22}})
  • Risk register and risk treatment plan ({{LINK:VA-09}})

5. Process

  1. Record: create the nonconformity in the ISMS tool ({{TOOL_NAME}}) with origin, description and affected area.
  2. Respond immediately: decide the correction to control the deviation and how to deal with its consequences.
  3. Analyse the cause: determine the cause and evaluate whether similar nonconformities exist or could occur elsewhere.
  4. Define corrective action: decide the action with a responsible role and a due date; size it to the cause, not to the symptom.
  5. Implement and follow up: track implementation in {{TOOL_NAME}}; delay escalates to {{ROLE_ISB}}.
  6. Review effectiveness: after the defined effectiveness interval, verify that the cause has been eliminated; adjust risks, controls and documents where necessary.
  7. Close: document and retain the nature of the nonconformity, the actions taken and the result of the effectiveness review.

6. RACI

# Step R (execution) A (accountable) C (consulted) I (informed)
1 Record Reporting person / auditor {{ROLE_ISB}} - -
2 Respond immediately Business unit {{ROLE_ISB}} {{ROLE_IT_LEAD}} -
3 Analyse the cause {{ROLE_ISB}} {{ROLE_ISB}} Business unit -
4 Define corrective action {{ROLE_ISB}} {{ROLE_MANAGEMENT}} Business unit -
5 Implement and follow up Action owner {{ROLE_ISB}} - {{ROLE_MANAGEMENT}}
6 Review effectiveness {{ROLE_ISB}} {{ROLE_ISB}} Business unit {{ROLE_MANAGEMENT}}
7 Close {{ROLE_ISB}} {{ROLE_ISB}} - -

7. Result & evidence

Action register with root cause analysis, due dates and documented effectiveness review in {{TOOL_NAME}}. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).

8. Key performance indicators (KPI)

  • Number of open nonconformities by age
  • On-time completion of corrective actions
  • Share of actions with confirmed effectiveness
  • Recurrence rate of similar nonconformities
  • Corresponding policy: {{LINK:R03}}
  • Internal audits: {{LINK:VA-15}}
  • Management review and metrics: {{LINK:VA-22}}
  • Incident response: {{LINK:VA-01}}
  • Technical security baseline: {{LINK:BASELINE}}