Correction and corrective action
A correction fixes the immediate problem, for example removing access that should have been revoked. A corrective action addresses why it happened, for example by connecting the HR leavers process to account deprovisioning so that it cannot happen again. Auditors expect both.
The steps
ISO 27001 (clause 10.2) requires the organisation to react to the nonconformity and deal with its consequences, review it and identify its root cause, check whether similar problems exist or could occur elsewhere, implement the action, review its effectiveness and update the ISMS if needed. Each step must be recorded.
Finding the root cause
Simple techniques work well: asking why repeatedly until the underlying cause appears, or mapping causes by people, process and technology. A root cause of human error usually means the analysis stopped too early; the real cause is often a missing process, unclear ownership or a lack of automation.
After an audit
When a certification auditor raises a nonconformity, the organisation must submit a corrective action plan within an agreed period. Major nonconformities must be resolved before the certificate is issued or maintained. Corrective actions also follow internal audits, security incidents and the management review.




