Skip to main content
To KTH's start page

Phase 4: Act

This page describes the improvement phase, Act, in KTH’s information security work according to the Plan–Do–Check–Act (PDCA) model. In this phase, improvements are decided on and initiated based on the results of the follow‑up.

The improvement phase assumes that the Check phase has been completed and that clear documentation is available, such as incident summaries, audit results, deviations, and identified improvement areas. These inputs form the basis for decisions on how the information security work needs to be adjusted and strengthened.

The focus of the Act phase is on correcting deviations, improving existing safeguards, and developing processes, instructions, and role responsibilities. The work is led by the CISO in cooperation with management and relevant parts of the organisation. Lessons learned from incidents and follow‑ups are actively used to strengthen KTH’s overall information security posture.

Based on the reports and analyses from the Check phase, management and the CISO decide how deviations shall be managed and develop an improvement plan. This plan is based on audits, incident handling, and other deviations from previously established objectives and plans. Governance documents, guidelines, and processes are updated as needed to ensure that information security governance remains effective and relevant.

The Act phase also documents experiences from areas that have functioned well, so they can be carried forward into the next cycle. For areas where outcomes have not met expectations, root causes are analysed, such as unclear objectives, inadequate measurements, non‑compliance with procedures, or changed conditions. The result is a set of recommendations and prioritised actions that feed directly into the next Plan phase, thereby completing and restarting the PDCA cycle.