ISMS Monitoring and Measurement (Clause 9.1)

This article provides guidance on how to monitor information security performance and effectiveness as well as examples

Written By Micah

Purpose

Clause 9.1 of ISO 27001 establishes two aspects to be monitored (or watched) and measured (assigned a value): information security performance and ISMS effectiveness. This article provides step-by-step guidance on how to build and document monitoring and measurement activities.

After working through these guidelines, the organization will have defined its unique procedures for monitoring and measurement.

Guidelines

  1. What will be monitored: Identify relevant business results and processes that can be affected by variations in information security performance. This may include information security controls and processes, mandatory requirements, and contractual obligations.

    1. Examples: Control performance - either self-assessed or independently audited, review for adherence to a regulation (such as CCPA or GDPR), internal audit of conformance with a major contract (Microsoft SSPA), alignment with stated Objectives

  2. Methods used in monitoring: Choose the methods you feel most comfortable with, whether manual, mechanical, or software. Methods will be individual to each organization, increasing the likelihood that users will correctly conduct monitoring. The chosen method must be verifiable to ensure that it can produce comparable and repeatable results.

    1. Examples: manual control self-assessment, independent audits, availability monitoring software product

  3. When to monitor: This process will also be individual to your organization as different needs require different monitoring frequencies or times. For example, your chosen application may have monitoring points at data input, processing, or output, affecting when and how often monitoring will be done.

    1. Example: Annual internal controls audit, weekly vulnerability scan, the annual pen test, daily intrusion detection alerting

  4. When results must be analyzed and evaluated: To ensure the addition of business value, monitoring results must be considered in decisions and actions at the proper times. Considering these too soon or too late may result in unnecessary effort, wasted resources, or loss of opportunities.

    1. Examples: Per established SLAs, when audit findings are not addressed after x days, Critical and High Pen test results,

  5. Who must analyze and evaluate results: Generally speaking, individuals on the operational level will perform the analysis, while management-level individuals will perform evaluations.