A customer complaint reveals that data subject requests were not handled within the promised timeframe. The ISMS manager wants to treat this as a source of nonconformity. Why is a complaint a valid trigger under the ISMS improvement process?
- A.Complaints are only relevant to quality management systems, not information security
- B.Nonconformities can arise from many sources including complaints, audits, incidents, and monitoring; a complaint may reveal a failure to meet a requirement the ISMS committed to
- C.A complaint can only be acted upon if it is also raised during an internal audit
- D.Complaints must be escalated to the certification body before any action is taken
Why B is correct
Nonconformities surface from multiple sources: internal/external audits, security incidents, customer or interested-party complaints, and monitoring/measurement results. A complaint indicating a missed commitment is a legitimate input that should be evaluated through the Clause 10.2 process.
Know someone studying for ISO 27001? Send them this one.