An organization wants a single source-of-truth for all nonconformities regardless of origin. Which combined set of inputs should feed this register to satisfy a comprehensive Clause 10.2 process?
- A.Only deviations identified during the annual management review. This step is scheduled for the management review meeting rather than for the Do phase.
- B.Only findings raised by the external certification body
- C.Only security incidents reported by the SOC
- D.Internal and external audit findings, security incidents, complaints, and monitoring/measurement deviations
Why D is correct
Nonconformities arise from multiple channels. A comprehensive register consolidates audit findings (internal and external), incidents, complaints from interested parties, and deviations detected through monitoring and measurement, ensuring all sources feed one corrective action process.
Know someone studying for ISO 27001? Send them this one.