Skip to content
atlas

Continuous improvement (PDCA)

Also known as: PDCA, Plan-Do-Check-Act, Deming cycle, continual improvement

A repeating four-step loop - Plan, Do, Check, Act - for getting a little better each round.

Draft - this entry has not been reviewed yet.

Formal

A repeating management method, made widely known by W. Edwards Deming, in which changes are planned from goals and risks, carried out, measured against those goals, and the lessons acted on before the next round begins.

In plain English

Like a cook perfecting a dish - make it, taste it, adjust the seasoning, and cook it again next week a little better.

In practice

The IT lead at a Danish upper-secondary school plans a phishing course for teachers, runs it, sees the click rate fall in every subject group but one, and changes the format for that group next term.

Why it matters

Threats and organisations keep changing, so security work is never finished; without a built-in loop, measures that fitted last year quietly stop fitting.

Technical deep dive

The cycle descends from Walter Shewhart's 1939 description of quality control as a loop of specification, production and inspection. W. Edwards Deming presented a version of it in his 1950 lectures to Japanese engineers and managers, and Japanese practitioners recast it as Plan-Do-Check-Act. Deming himself called it the Shewhart cycle and later argued for Plan-Do-Study-Act (PDSA), because "check" suggests inspection while "study" implies analysing results against a prediction. Both forms remain in use, and neither is tied to information security.

In security management the cycle became explicit through ISO/IEC 27001:2005, whose introduction presented the ISMS as a PDCA model. The 2013 edition removed that section when it adopted the common structure for ISO management system standards and no longer prescribed a particular improvement model, but the loop is still built into the clause order of the 2022 edition: Plan corresponds to clauses 4-7 (context, leadership, planning including risk assessment and treatment, support), Do to clause 8 (operation), Check to clause 9 (monitoring and measurement, internal audit, management review) and Act to clause 10 (improvement). In the 2022 edition clause 10.1 is continual improvement and 10.2 nonconformity and corrective action, the reverse of the 2013 order.

ISO uses "continual" rather than "continuous" deliberately: improvement happens in recurring steps, not as an unbroken flow. ISO/IEC 27000 also separates a correction, which fixes a detected nonconformity, from a corrective action, which removes its cause to prevent recurrence; an audit finding closed with only a correction leaves the Act step incomplete. Evidence an auditor expects includes a nonconformity log with root-cause analysis, follow-up on effectiveness and management review outputs that change something.

The typical failure is a loop that turns but does not steer: Check degenerates into verifying that documents exist, and Act never feeds back into the next Plan, so the same findings reappear every year. Another is running a single annual loop for everything, when threats move faster than that. Mature organisations nest loops at different speeds, for example weekly for vulnerability management, after every incident as lessons learned, and yearly for the risk assessment and management review. Related loops such as the OODA loop (observe, orient, decide, act) in incident response or lessons-learned phases in NIST incident handling guidance serve the same purpose at operational speed, while PDCA remains the governance-level rhythm.

Relationships

Implemented by
Lessons learned
Mandated by
ISO 27001

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022, Clause 10 (Improvement) · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.