Phase 3: Check
This page describes the follow‑up phase, Study (Check), of KTH’s information security work according to the Plan–Do–Check–Act (PDCA) model. In this phase, the effectiveness of the implemented security measures and working methods is monitored and evaluated.
In the Check phase, the information security work implemented during the Do phase is reviewed and evaluated. This phase requires that decided security measures have been implemented and that the information classification process is applied in practice. The objective is to ensure that safeguards function as intended, that established rules and requirements are followed, and that deviations and improvement needs are identified.
The follow‑up provides a consolidated view of how the information security work performs over time. This includes reviewing the status of implemented security controls, identified deviations and corrective actions, and information security incidents along with lessons learned. Results from monitoring, measurements, controls, and audits are used to assess how well established requirements and objectives are being met.
The Check phase shall result in documented summaries such as review or audit reports, deviation reports, and compilations of incidents. Identified improvement areas and management feedback are documented and form the basis for decisions and prioritisation in the next phase, Act.