ISO 27005:2022
Leveraging related ISMS processes – ISO 27005:2022

ISO 27005:2022 10.8: Continual improvement

Input: all risk information from risk management. Action: monitor, review and improve the risk management process as needed. Trigger: the wish to improve and mature from lessons learned. Output: a process that stays relevant to business objectives, or an updated one. Ongoing review keeps context, assessment and treatment outcomes and management plans suited to circumstances; agreed improvements or actions to improve compliance with the process are notified to responsible managers, who are assured no risk is missed or understated and that decisions give a realistic understanding and ability to respond. Change management feeds the risk process continually so changes to information systems that could modify risk are picked up, even altering assessment activities. The criteria used to measure risk are verified regularly against business objectives, strategies, policies and changes in business context, covering legal and environmental context, competition, the assessment approach, asset values and categories, consequence, likelihood, evaluation and acceptance criteria, the resources needed and the total cost of ownership; assessment and treatment resources remain available to review risk, address new threats and vulnerabilities and advise management. Monitoring may change approach, method or tools according to risk maturity, changes found, the assessment iteration, the purpose of risk management (such as continuity, incident resilience or compliance) and its object (organisation, business unit, process, technical implementation, application, internet connection); the cycles of 5.2 apply.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 35 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISO-37002-10.2 Continual improvement
  • ISO37002-10.1 Continual Improvement
  • ISO-39001-10.2 Continual improvement
  • ISO39001-10.2 Continual Improvement
  • ISO-41001-10.2 Continual improvement
  • ISO41001-10.2 Continual Improvement
  • ISO-50001-10.2 Continual improvement
  • 10.2 Continual improvement

ISO 56002 · 2 controls

  • ISO-56002-10.3 Continual improvement
  • ISO56002-10.2 Continual improvement

ISO/IEC 27003:2017 · 2 controls

  • 27003-10.2 Continual Improvement
  • ISO27003-10.1 Nonconformity and corrective action
  • AS9100D-10.3 Continual Improvement
  • SPC1-A.1 Continual Improvement
  • BS65000-10.1 Continual Improvement

ISO 10006:2003 · 1 control

  • 8.3 Continual improvement

ISO 14001:2015 · 1 control

  • 10.3 Continual improvement

ISO 14004:2016 · 1 control

  • 10.3 Continual improvement

ISO 22000:2018 · 1 control

  • 10.2 Continual improvement

ISO 22301:2019 · 1 control

  • 10.1 Nonconformity and corrective action
  • ISO-22313-10.2 Continual improvement

ISO 22320:2018 · 1 control

  • ISO-22320-4.8 Continual improvement

ISO 27701:2019 · 1 control

  • 5.8.2 Continual improvement

ISO 30401 · 1 control

  • ISO30401-10.2 Continual improvement

ISO 31000:2018 · 1 control

  • 4.h Continual improvement

ISO 37001:2016 · 1 control

  • 10.2 10.2 Continual improvement

ISO 37301:2021 · 1 control

  • 10.1 Continual improvement

ISO 45001:2018 · 1 control

  • 10.3 Continual improvement

ISO 55001:2014 · 1 control

  • 10.3 Continual improvement

ISO 9001:2015 · 1 control

  • 10.3 Continual improvement

ISO/IEC 23894:2023 · 1 control

  • ISO23894-4.8 Continual Improvement

ISO/IEC 27031:2011 · 1 control

  • 27031-10.1 Continual Improvement
  • ISO27557-10.1 Continual Improvement

ISO/IEC 42001:2023 · 1 control

  • 10.1 Continual improvement

ITIL 4 · 1 control

  • GM-CI-1 Continual Improvement

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Leveraging related ISMS processes – ISO 27005:2022

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.