Skip to content

Improve: what you record here and why

Last checked on

The Improve group is where you record what went wrong, what you learnt from it and whether you are making progress: incidents, nonconformities, internal audits, management reviews and objectives.

Why this protects your organisation

No organisation runs without mistakes. What customers and auditors want to see is that you notice them, remove the cause and check that the fix held. This group makes that loop visible, from the first signal to the decisions your leadership takes. In ISO 27001 it covers chapter 9 (evaluation) and chapter 10 (improvement), plus the objectives of clause 6.2.

Steps

  1. Start by setting a few objectives under Objectives, so you know what you are working towards.
  2. Record security incidents under Incidents as they happen.
  3. Turn anything that did not go as agreed into a nonconformity under Nonconformities, and follow it up until a check shows the fix works.
  4. Plan this year's internal audits under Internal audits and record the findings once each audit is done.
  5. Hold a management review at least once a year under Management reviews and establish it.

The screens in this group feed into each other. An incident or an audit finding can become a nonconformity, and everything comes together in the management review.

  • Incidents: security incidents with their severity, who is handling them and a timeline of what happened, from first report to archive.
  • Nonconformities: something that did not go as agreed, with the immediate correction, the root cause, the corrective actions and the check on whether they worked.
  • Internal audits: your audit programme per year, with an independent auditor, findings per requirement and a PDF report.
  • Management reviews: the fixed agenda your leadership works through, with summaries Trustbird prepares when you open the review, and the decisions taken.
  • Objectives: what you want to achieve, how you measure it and by when, with a log of progress.

Follow-up work on incidents, nonconformities and management reviews is an ordinary task, which you also find under Tasks in the Today group. That way everything still to be done sits in one place, wherever it came from.

If it does not work

I cannot create or change anything in this group

Advisors can only read, unless the workspace owner gives them edit rights for the module behind the screen. That is Improvement for nonconformities, internal audits and management reviews, Risks and controls for incidents, and Policies and documents for objectives.

There is a number next to Nonconformities in the menu

That is the number of nonconformities still open. It disappears once they are all closed.

Read next