Introduction
At the core of ISO 27001 and BSI IT-Grundschutz lies a simple but powerful approach to continuous improvement: the Plan–Do–Check–Act (PDCA) cycle. Also known as the Deming cycle, it is a systematic four-step model for problem solving and process improvement.
The PDCA cycle starts with the Plan phase, where a problem or opportunity for improvement is identified and a plan is created. In the Do phase, this plan is implemented. During the Check phase, results are evaluated and compared to the original objectives. In the Act phase, corrective actions and improvements are derived and standardised. The cycle then starts again – enabling continuous improvement.
PDCA is a key element in:
ISO 27001 – the international standard for information security management systems (ISMS)
BSI IT-Grundschutz – the German baseline security standard
By applying PDCA, organisations can systematically improve their information security and stay aligned with ISO 27001 and BSI IT-Grundschutz.
Key Takeaways
Structured improvement model: PDCA provides a clear framework for continuous improvement of processes and systems.
Core method in ISO 27001 & BSI IT-Grundschutz: It forms the methodological backbone of information security management in both international and national standards.
Iterative cycle: The four phases – Plan, Do, Check and Act – drive ongoing adjustment and optimisation based on measurable results.
Engagement & quality assurance: The model promotes staff involvement, improves quality and reduces errors and inefficiencies.
What Is the PDCA Cycle?
The PDCA cycle (Deming cycle) is an iterative management model for continuous improvement. It consists of four phases:
Plan
Do
Check
Act
Organisations use the model to continuously monitor, analyse and improve their processes, aiming to increase quality, efficiency and customer satisfaction.
Phase 1: Plan
The Plan phase lays the foundation for the entire cycle.
Typical activities:
Identify issues, risks or improvement opportunities
Analyse the current situation (audits, KPIs, interviews, process data)
Define clear objectives and target values
Analyse causes and derive hypotheses
Develop a concrete action plan (who, what, by when, with which resources?)
Define KPIs and benchmarks to measure success
A solid Plan phase ensures that everyone understands the goals, roles and responsibilities and that the next steps are based on valid assumptions.
Phase 2: Do
The Do phase is where the plan is implemented.
Typical activities:
Implement planned measures (controls, process changes, new tools)
Run pilots or tests (proof of concept)
Train staff involved in the process
Document execution and deviations
Collect data for evaluation in the Check phase
Do is not just “doing things” – it is controlled implementation with documentation, so that later analysis is meaningful.
Phase 3: Check
In the Check phase, the effectiveness of the measures is evaluated.
Typical activities:
Compare actual vs. target values
Analyse performance indicators and reports
Conduct quality checks and effectiveness reviews
Gather feedback from employees, stakeholders or customers
Identify deviations, causes and lessons learned
If results do not meet expectations, root causes must be analysed. If objectives are achieved, success factors become visible and can be used in the Act phase.
Phase 4: Act
The Act phase translates insights from Check into decisions and adjustments.
Typical activities:
Standardise effective measures (policies, processes, SOPs)
Correct or replace ineffective measures
Document lessons learned
Set new or refined objectives for the next PDCA cycle
This creates a learning organisation: every cycle improves maturity and resilience.
PDCA in ISO 27001
ISO 27001 uses PDCA as the underlying model for the information security management system.
Plan: Context analysis, risk assessment, definition of information security objectives and controls (Statement of Applicability, ISMS plan).
Do: Implementation of controls, processes, responsibilities and security policies.
Check: Internal audits, monitoring, metrics, management reviews, non-conformity analysis.
Act: Corrective and improvement actions, updates to risk treatment and documentation.
Through repeated PDCA cycles, the ISMS is continuously adapted to new threats and changes in the organisation.
PDCA in BSI IT-Grundschutz
BSI IT-Grundschutz also relies on PDCA, focusing on a structured security process.
Plan: Define security objectives, scope, perform structure analysis and protection needs assessment, select BSI modules and measures.
Do: Implement the selected measures, establish processes and responsibilities, document the security concept.
Check: Perform Grundschutz checks, monitor effectiveness, analyse gaps and deviations.
Act: Adjust measures, update the security concept and documentation, close identified gaps.
PDCA ensures that information security is not a one-time project but a continuous management discipline.
Benefits of the PDCA Cycle
Clear structure for continuous improvement and problem solving
Increased process efficiency and quality
Reduced errors and waste
Stronger culture of responsibility and learning
Better auditability and compliance capability
Challenges in Practice
Common obstacles:
Lack of management commitment
Insufficient understanding of PDCA
Poor or incomplete data
Resistance to change
Mitigation approaches:
Training & awareness
Transparent communication of goals and benefits
Proper tools for data collection and analysis
Active involvement of staff in all phases
Step-by-Step to a Certifiable ISMS (with fuentis)
With the fuentis ISMS tool, PDCA becomes operational:
Multi-compliance ISMS A full ISMS solution guiding you to ISO 27001 certification while also covering BSI IT-Grundschutz, TISAX® or NIS2.
Automated processes Guided and automated workflows that lead you step by step through implementation and certification – even without prior ISMS expertise.
Review questionnaires Simple, customisable questionnaires to determine protection needs and assess risks quickly and transparently.
Personal support Experienced consultants support you from the first gap analysis all the way to audit preparation.
Conclusion
The PDCA cycle is an essential instrument for continuous improvement in information security. Its use in ISO 27001 and BSI IT-Grundschutz demonstrates its effectiveness and flexibility.
By applying PDCA consistently, organisations can:
systematically plan and control security measures
continuously improve their ISMS
adapt to evolving risks and threats
foster a culture of ongoing improvement

Srdan Manasijevic
CEO
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.


