SIST ISO/IEC 27004:2018 PDF
Information technology -- Security techniques -- Information security management -- Monitoring, measurement, analysis and evaluation
Information technology -- Security techniques -- Information security management -- Monitoring, measurement, analysis and evaluation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 63
- Дата публикации:
- 23 октября 2018 г.
- ICS:
- 03.100.70
- Технический комитет:
- ITC - Information technology
ISO/IEC 27004:2016 provides guidelines intended to assist organizations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes: a) the monitoring and measurement of information security performance; b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls; c) the analysis and evaluation of the results of monitoring and measurement. ISO/IEC 27004:2016 is applicable to all types and sizes of organizations.
Abstract
Overview
ISO/IEC 27004:2016 - Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation - provides practical guidance for measuring information security performance and the effectiveness of an Information Security Management System (ISMS). It is explicitly intended to help organizations fulfil the monitoring and measurement requirements of ISO/IEC 27001:2013 (clause 9.1). The standard is applicable to all types and sizes of organizations and includes a measurement model, examples and processes for establishing a repeatable metrics program.
Key topics and requirements
- Purpose: Enable evaluation of information security performance and ISMS effectiveness to support governance, management decisions and continual improvement.
- What to cover: Monitoring and measurement of information security performance, and measurement of ISMS processes and controls.
- Measurement lifecycle: Guidance on identifying information needs, creating and maintaining measures, establishing procedures, collecting data, analysing results, evaluating effectiveness and retaining evidence.
- Validity of results: Emphasizes producing comparable and reproducible measurements (scope stability, consistent methods, handling subjective inputs).
- Types of measures: Distinguishes performance measures and effectiveness measures and provides examples and templates (Annexes A–C).
- Roles & timing: Maps to ISO/IEC 27001:2013, 9.1 requirements for determining what to monitor, how/when to measure, and who analyses and evaluates results.
- Documentation: Requires retaining appropriate documented information as evidence of monitoring and measurement activities.
Applications and who uses it
- ISMS managers and Information Security Officers: to design and run security metrics programs aligned with ISO/IEC 27001 audits.
- Risk and Compliance teams: to demonstrate control effectiveness and fulfil audit evidence requirements.
- CIOs and Executives: for performance reporting and informed decision-making about security investments.
- Internal auditors and consultants: to assess measurement approaches, ensure validity and recommend improvements.
- Typical use cases: establishing security KPIs, validating control effectiveness, supporting continual improvement, producing management-ready security dashboards, and preparing for ISO/IEC 27001 certification or surveillance audits.
Related standards
- ISO/IEC 27001:2013 - ISMS requirements (clause 9.1 mapping)
- ISO/IEC 27000 - ISMS vocabulary and fundamentals
- ISO/IEC 15939 - Measurement process framework referenced as theoretical foundation
ISO/IEC 27004:2016 is essential for organizations that want a structured, auditable approach to information security measurement, ensuring meaningful, valid metrics that support ISMS effectiveness and continuous improvement.
Технические детали
- SKU
- SIST ISO/IEC 27004:2018
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS EN ISO/IEC 27000:2020
ОтменёнInformation technology. Security techniques. Information security management systems. Overview and vocabulary
1 Scope This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is a…