Nonconformity vs Incident
Nonconformity vs Incident
These are notoriously exchanged with each other, although they are far not the same.
A nonconformity is the non-fulfillment of a requirement. A requirement may come from the standard, a law or an interested party (a customer, an authority or anyone else). The standard requirement to correct this is to carry out corrective action, which is defined in the standard body.
An incident is an unwanted or unexpected information security event that has a significant probability of compromising business operations and threatening information security. Treat incidents by the incident management process, which is defined in Annex A. In the IT the term error is often used, but in information security it is an availability and/or integrity incident.
Are these completely independent? Of course, not – an incident may happen randomly (e.g. a computer hardware error) or can be caused by a nonconformity. Investigating the cause of an incident sometimes reveals a nonconformity in the background. For example, a missing patch could lead to a successful ransomware attack or theft of a computer may occur because the office door was not locked. In cases like this the incident handling must be followed by corrective action.
The two key elements of corrective action are root cause analysis and determination if similar nonconformities exist or could potentially occur elsewhere. There is no corrective action without these.
The preventive effect is common in incident handling and corrective action. As part of incident handling, the standard requires that knowledge gained from information security incidents shall be used to strengthen and improve the information security controls. Corrective action also requires evaluation of the need for action to eliminate the causes of nonconformity, in order that it does not recur or occur elsewhere.
10/07/2025