Internal audits at planned intervals must determine whether the ISMS conforms to the organization's own requirements and ISO/IEC 27001, and whether it is effectively implemented and maintained. The audit program must cover frequency, methods, responsibilities, planning, and reporting; each audit needs criteria and scope, and auditor selection must protect objectivity and impartiality.
Top management must review the ISMS at planned intervals. Required inputs include previous actions, relevant context and interested-party changes, performance feedback, interested-party feedback, risk-assessment results, treatment-plan status, and improvement opportunities. Retain the resulting decisions on improvement opportunities and needed ISMS changes.
When a nonconformity occurs, react to it, address consequences as applicable, evaluate and address causes, review corrective-action effectiveness, and change the ISMS if needed. Retain the nature of the nonconformity, actions taken, and corrective-action results.