Performance Monitoring
Performance Monitoring
The list in ISO 27001 Clause 9.1 summarises the minimum metric characteristics required to achieve the objectives of performance measurement.
Organizations commonly use key performance indicators (KPIs) to measure effectiveness and track progress toward objectives. A few examples of good KPIs are the percentage of security tasks completed on time, the availability of key ICT resources, or the number of security incidents. Evidence-based indicators should be assigned not only to controls, but also to requirements defined by the standards body. These can include, for example, nonconformities identified in audits or employee policy acknowledgement rates.
Implementation Support
Organizations struggle with how to select the right KPIs. Instead of setting meaningless metrics, first define the information needs that support operational or business decisions. Then select the KPIs that best address those information needs.
ISO 27004 is a guidance standard, and its 2016 edition is the current version. This document is intended to assist organizations in evaluating information security performance and the effectiveness of an ISMS in order to fulfil the requirements of ISO 27001 on monitoring, measurement, analysis and evaluation. It is long overdue for an update, as it still refers to the 2013 edition of the certification standard. Nevertheless, this reference is not substantial, and the content of the standard can still be effectively used from both methodological and illustrative perspectives.
Continuous Monitoring
The obligation for periodic monitoring appeared only in the latest editions of the standard. This shall be supported by a stable set of KPIs. If you change a metric or the way you obtain it, then to retain comparability, parallel application of both the original and the changed KPI (or method) may be required for a while.
Some metrics may seem useless, showing constantly good (excellent) values. But don’t assume it will remain so. As the financial industry puts it, past performance is not indicative of future results. If the value of an indicator is business-critical, keep monitoring it.
Keep It Simple
A long time ago, there was a misconception that every Annex A control should have a KPI assigned. In fact, there is no requirement regarding the number of metrics, but the set has to be representative and informative. It is impracticable, costly and counterproductive to measure too many or the wrong attributes. Start with a few key metrics before expanding.
KPIs should be cost-effective: the effort required to measure and evaluate them should match the business value they deliver.
Actionable Data
Ensure results are valid and consistent, and that they lead to management action. Don’t monitor a KPI just because it is in ISO 27004. Organizations and priorities are different. A metric is unnecessary if changes in it don’t contribute to business decisions.
Reaching the desired values of performance metrics can be set as an objective, but it is not mandatory.
13/07/2026