Remediation and the Continual Process Improvement Cycle

Organizations use various improvement models, such as the PDCA and Six Sigma models, to enhance their cybersecurity posture and operational resilience over time.

4 slides · 2 min read · Domain 6

Slide 1

Continuous process improvement models primarily focus on incremental improvements, but they can be instrumental in achieving transformational changes.

Plan-Do-Check-Act (PDCA) is a well-known improvement model that follows four phases:

1. Plan. Decide what needs to be done, establish the objectives, and determine the processes needed to implement the change. [

2. Do. Execute the plan.

3. Check. Evaluate the results of the plan. This may happen through statistical measures of performance, observations, or evaluations.

4. Act (Adjust). Identify the root causes of failure, reevaluate risk, and determine the baseline for measuring future performance.

The Six Sigma's five-phase approach has gained widespread use:

1. Define. Clearly define the problem in terms of the customer's requirements.

2. Measure. Collect data to measure the current process and assess performance.

3. Analyze. Examine the data to determine relationships, causality, and the root cause of the problem.

4. Improve. Develop and implement solutions to address the root causes and improve the process, potentially piloting the new process.

5. Control. Implement control systems to continuously monitor the process and prevent deviations.

Both PDCA and Six Sigma models employ cyclical processes aimed at continuous improvement. These iterative approaches enable organizations to refine their processes and strive for excellence. In various ways, the major security frameworks apply continuous process improvement methods to better align control performance with risk. The predictability and repeatability of the process allows the organization to adapt to change based on the cycle. However, no single approach fits every organization. Tailoring a continual process improvement approach to an organization entails considering the organization's culture, established risk management processes, prioritization and decisionmaking approaches, compliance requirements, performance monitoring, and larger change management activities. Continual process improvement is as much a way of thinking as it is a process and must be embraced by the entire organization to be effective.

Test this domain