PDCA cycle
The PDCA cycle (Plan-Do-Check-Act) is the four-stage feedback loop used to plan, implement, review and continually improve an information security management system.
The PDCA cycle traces back to the statistician Walter A. Shewhart and was popularised by W. Edwards Deming as a model of continual improvement. It describes a control loop with four stages: "Plan" establishes the organisational context, interested parties, scope, risks and objectives and derives controls from them; "Do" introduces and operates the planned controls, policies and processes; "Check" uses metrics, internal audits and the management review to verify whether the controls are effective and the objectives are being met; "Act" corrects deviations, removes root causes and feeds improvements back into the next iteration. For an ISMS this loop is the actual engine. Without it, information security remains a one-off project; with it, it becomes a permanently managed process.
The cycle is deeply embedded in the standards, even though ISO/IEC 27001:2022 no longer prescribes the term PDCA explicitly. The harmonised structure shared by management system standards still follows it clearly: clauses 4 to 6 (context of the organisation, leadership, planning including risk assessment and risk treatment) form the Plan stage, clauses 7 and 8 (support, operation) the Do stage, clause 9 (performance evaluation with monitoring, measurement, internal audit and management review) the Check stage, and clause 10 (improvement, covering nonconformity and corrective action as well as continual improvement) the Act stage. The German BSI Standard 200-1 likewise describes the security process as a lifecycle of planning, implementation, effectiveness review and optimisation. Crucially, the cycle does not only run at the level of the ISMS as a whole: smaller loops apply per control, per security incident and per risk.
Supervisory law thinks in control loops too. Article 21 of the NIS2 Directive (EU) 2022/2555 requires an all-hazards, risk-based approach and, in paragraph 2(f), explicitly names policies and procedures to assess the effectiveness of cybersecurity risk-management measures — precisely the Check stage. The German transposition in the BSIG (NIS2UmsuCG) obliges the management body to approve the measures and to supervise their implementation; in practice the timetables for individual registration and evidence duties are still moving, so specific deadlines should always be checked against the current legal status. In day-to-day work the PDCA cycle rarely fails at Plan and Do, but at weak Check and Act stages: audits are carried out, yet findings are never closed out with a root-cause analysis and dated corrective actions. A robust cycle therefore needs named owners, a fixed cadence, measurable ISMS metrics and a documented feedback path into the next planning round.
Legal Basis
ISO/IEC 27001:2022, clauses 4–10, in particular 9.1–9.3 and 10.1–10.2; ISO/IEC 27002:2022; BSI Standard 200-1; Art. 21(2)(f) NIS2 Directive (EU) 2022/2555; Sections 30 and 38 BSIG (German NIS2 Implementation Act)
Practical Example
A mechanical engineering company with 600 employees qualifies as an important entity under NIS2 and runs an ISMS certified to ISO/IEC 27001. The information security officer paces the cycle annually. In the Plan stage she updates the risk assessment after a new remote maintenance access for production machinery is introduced and derives two objectives: multi-factor authentication for all external access, and a 95 percent patch rate for critical vulnerabilities within 14 days. In the Do stage the controls are implemented, supplier contracts are amended and staff are trained. In the Check stage the internal audit and the metrics show that MFA is in place, but the patch rate reaches only 78 percent because machine PCs on the production network can only be updated during maintenance windows. In the Act stage the root cause is documented, an additional quarterly maintenance window is approved and network segmentation is strengthened as a compensating control; the management review releases the resources, and the objective moves into the next iteration with an adjusted measurement method.