SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Clause 9.1 - measurement in ISO 27001 toolkit

  Quote
Guest
Guest user Created:   Jan 15, 2016 Last commented:   Jan 15, 2016

Clause 9.1 - measurement in ISO 27001 toolkit

I was reviewing the ISO 27001 standard and was reading section 9.1 about monitoring, measurement, analysis, and evaluation. How does your documents deal with this? I know at the end of some of the documents, I've seen sections called "managing records kept on the basis of this document". This isn't how you are trying to monitor the effectiveness of processes and controls is it? Have I overlooked a document... I'm not really seeing anything that addresses 9.1. I guess when I read 9.1 about monitoring, measurement, analysis, and evaluation, I'm thinking it is something more driven around key performance indicators (KPI's), Service level agreements (SLA's), or something that would show stats about the effectiveness and relevancy where there was more of a system that gave analytics of some type. What are your thoughts?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Jan 15, 2016

Answer:
In our documentation toolkit there are basically two levels of measuring: first is on the level of the documents - in the last section of most of our documents, you'll find a sentence: "When evaluating the effectiveness and adequacy of this document, the following criteria need to be considered:..." and then a couple of items to be measured.

The second level is for the controls - in the Statement of Applicability you should set the objectives for each control, and then you can measure up to which level those objectives have been fulfilled.

These two levels are applicable for smaller and mid-size companies - of course, for larger companies you might develop a more precise and more comprehensive systems like KPIs or Balanced Scorecards.

These materials will also help you:
- How to perform monitoring and measurement in ISO 27001 https://advisera.com/27001academy/blog/2015/06/08/how-to-perform-monitoring-and-measurement-in-iso-27001/
- ISO 27001 control objectives – Why are they important? https://advisera.com/27001academy/blog/2012/04/10/iso-27001-control-objectives-why-are-they-important/
- ISO 27001 and ISO 27004: How to measure the effectiveness of information security? https://advisera.com/27001academy/webinar/iso-27001-iso-27004-measure-effectiveness-information-security-free-webinar/
- ISO 27001 Foundations Course: https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 15, 2016

Jan 15, 2016

Suggested Topics

Guest user Created:   Sep 24, 2021 ISO 27001 & 22301
Replies: 1
0 0

Documentation of requirements

Guest user Created:   Jun 02, 2022 ISO 27001 & 22301
Replies: 1
0 0

Framework question