ISO 27001 Major vs Minor Nonconformity: What Changes?
Finding classification should reflect the audit scheme and the significance of the conformity failure.
Do not classify from intuition alone
Major and minor classification should follow the applicable audit and certification methodology. The label is not merely a synonym for high or low technical severity.
Look at the management-system failure
A widespread absence of a required process, repeated breakdown across the system, or failure that creates significant doubt about the ISMS can be more serious than an isolated record defect.
Evidence matters
The auditor should show the criteria, objective evidence and condition supporting the finding. Classification follows from the nature and extent of that nonconformity.
Technical severity and audit classification differ
A severe vulnerability can be a high business risk while the related audit finding classification depends on how the management system addressed the requirement and control.
Corrective action needs root cause
Fixing the sampled item is not always enough. The organisation should address why the control failed and verify the corrective action is effective.
Use the Readiness Review to define scope and the first assessment.