ISO/IEC 27004:2016
Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation
Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 63
- Дата публикации:
- 15 декабря 2016 г.
- Издание:
- ISO/IEC IS 27004 edition 2 version 1
- ICS:
- 03.100.70
ISO/IEC 27004:2016 provides guidelines intended to assist organizations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes: a) the monitoring and measurement of information security performance; b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls; c) the analysis and evaluation of the results of monitoring and measurement. ISO/IEC 27004:2016 is applicable to all types and sizes of organizations.
Abstract
Overview
ISO/IEC 27004:2016 - Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation - provides practical guidance for measuring information security performance and the effectiveness of an Information Security Management System (ISMS). It is explicitly intended to help organizations fulfil the monitoring and measurement requirements of ISO/IEC 27001:2013 (clause 9.1). The standard is applicable to all types and sizes of organizations and includes a measurement model, examples and processes for establishing a repeatable metrics program.
Key topics and requirements
- Purpose: Enable evaluation of information security performance and ISMS effectiveness to support governance, management decisions and continual improvement.
- What to cover: Monitoring and measurement of information security performance, and measurement of ISMS processes and controls.
- Measurement lifecycle: Guidance on identifying information needs, creating and maintaining measures, establishing procedures, collecting data, analysing results, evaluating effectiveness and retaining evidence.
- Validity of results: Emphasizes producing comparable and reproducible measurements (scope stability, consistent methods, handling subjective inputs).
- Types of measures: Distinguishes performance measures and effectiveness measures and provides examples and templates (Annexes A–C).
- Roles & timing: Maps to ISO/IEC 27001:2013, 9.1 requirements for determining what to monitor, how/when to measure, and who analyses and evaluates results.
- Documentation: Requires retaining appropriate documented information as evidence of monitoring and measurement activities.
Applications and who uses it
- ISMS managers and Information Security Officers: to design and run security metrics programs aligned with ISO/IEC 27001 audits.
- Risk and Compliance teams: to demonstrate control effectiveness and fulfil audit evidence requirements.
- CIOs and Executives: for performance reporting and informed decision-making about security investments.
- Internal auditors and consultants: to assess measurement approaches, ensure validity and recommend improvements.
- Typical use cases: establishing security KPIs, validating control effectiveness, supporting continual improvement, producing management-ready security dashboards, and preparing for ISO/IEC 27001 certification or surveillance audits.
Related standards
- ISO/IEC 27001:2013 - ISMS requirements (clause 9.1 mapping)
- ISO/IEC 27000 - ISMS vocabulary and fundamentals
- ISO/IEC 15939 - Measurement process framework referenced as theoretical foundation
ISO/IEC 27004:2016 is essential for organizations that want a structured, auditable approach to information security measurement, ensuring meaningful, valid metrics that support ISMS effectiveness and continuous improvement.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27004:2016
Похожие стандарты
Стандарты, упомянутые в описании