Home / ISO 27001 Glossary of Terms / Continual Improvement

Continual Improvement

11/09/2025

Author: Stuart Barker | ISO 27001 Expert and Thought Leader

Continual Improvement is a recurring process to enhance the effectiveness and efficiency of an organisation’s Information Security Management System (ISMS). In the context of ISO 27001, it’s about making ongoing, incremental changes to the ISMS to ensure it remains relevant, effective, and aligned with the organisation’s changing security needs and objectives.

Core Activities & Examples

  • Performance Monitoring and Measurement: Regularly collecting and analyzing data on security incidents, audit findings, and control performance. For example, tracking the number of failed login attempts or the time it takes to patch a system.
  • Audit and Review: Conducting internal and external audits to identify non-conformities and opportunities for improvement. The results of these audits are a primary driver for improvement actions.
  • Corrective Actions: Implementing changes to fix problems identified in audits or incident reports. For instance, updating a policy or re-training staff after a security breach.
  • Management Review: The top management of an organisation regularly reviewing the ISMS to ensure it’s still fit for purpose and to allocate resources for necessary improvements.

ISO 27001 Context

Continual improvement is the final stage of the Plan-Do-Check-Act (PDCA) cycle and is a mandatory requirement under ISO 27001 Clause 10.1 Continual Improvement of the ISO 27001 standard. It ensures that the ISMS doesn’t become static and provides a framework for learning from mistakes and adapting to new threats.

About the author

Stuart Barker is an information security practitioner of over 30 years. He holds an MSc in Software and Systems Security and an undergraduate degree in Software Engineering. He is an ISO 27001 expert and thought leader holding both ISO 27001 Lead Implementer and ISO 27001 Lead Auditor qualifications. In 2010 he started his first cyber security consulting business that he sold in 2018. He worked for over a decade for GE, leading a data governance team across Europe and since then has gone on to deliver hundreds of client engagements and audits.

He regularly mentors and trains professionals on information security and runs a successful ISO 27001 YouTube channel where he shows people how they can implement ISO 27001 themselves. He is passionate that knowledge should not be hoarded and brought to market the first of its kind online ISO 27001 store for all the tools and templates people need when they want to do it themselves.

In his personal life he is an active and a hobbyist kickboxer.

His specialisms are ISO 27001 and SOC 2 and his niche is start up and early stage business.