SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 27001 Control

  Quote
Guest
Guest user Created:   May 15, 2020 Last commented:   May 15, 2020

ISO 27001 Control

1. I wanted to know how we can measure the maturity of an ISO control when trying to assess its maturity level with something like CMMI.

2. How can we measure how effective is a control and how mature? Any resources that can help?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 15, 2020

1. I wanted to know how we can measure the maturity of an ISO control when trying to assess its maturity level with something like CMMI.

First is important for you to understand the criteria levels adopted, so you can define how you can evidence the control has achieved them. For example, using  the model defined by ISO/IEC 15504:

  • Level 0 – Incomplete: No process implemented or little/no evidence of any systematic achievement of the process purpose (control not implemented/control does not deliver expected results most part of the time)
  • Level 1 – Performed: The process achieves its expected purpose (control deliver expected results most part of the time)
  • Level 3 – Established: The process is implemented using a defined (standard) process that is capable of achieving the expected outcomes (control deliver expected results most part of the time and is performed in a similar way in all places where it is applied )
  • Level 4 – Predictable: The process operates within defined limits to achieve its expected outcomes (control deliver expected results with optimized resources)

This article will provide you a further explanation about maturity models and ISO 27001:

2. How can we measure how effective is a control and how mature? Any resources that can help?

The effectiveness and maturity of control can be measured against business-related objectives and KPIs (e.g., reduced incidents, through incident management, increasing customer satisfaction) and the costs related to its operation (the lower the better).

This article will provide you a further explanation about ISO 27001 KPIs:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 15, 2020

May 15, 2020