An organization wants a single source-of-truth for all nonconformities regardless of origin. Which combined set of inputs should feed this register to satisfy a comprehensive Clause 10.2 process?
- A.Only findings raised by the external certification body
- B.Internal and external audit findings, security incidents, complaints, and monitoring/measurement deviations
- C.Only security incidents reported by the SOC
- D.Only deviations identified during the annual management review
Why B is correct
Nonconformities arise from multiple channels. A comprehensive register consolidates audit findings (internal and external), incidents, complaints from interested parties, and deviations detected through monitoring and measurement, ensuring all sources feed one corrective action process.
Know someone studying for ISO 27001? Send them this one.