ISO/IEC 27003:2017 ISO27003-10.1: Nonconformity and corrective action
When a nonconformity arises, respond to it by containing and correcting it and handling its consequences where applicable; decide whether its causes must be removed so it neither returns nor appears elsewhere, by reviewing it, finding its causes and checking whether similar cases exist or could arise; take whatever action is needed; check that corrective action worked; change the ISMS if that is necessary; keep corrective action proportionate to the effect of the nonconformity; and keep documented evidence of what the nonconformity was, what was done and the outcome. Implementation points (general practice; the 27003 guidance text is not held): nonconformities come from audits, monitoring, incidents and complaints; correct first, then remove the cause and verify later.
This control maps to 50 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.