Our own servers in Europe · GDPR · Support in your language

Module 6 of 7 · ISO 27001 · Clause 9

Performance evaluation

This clause forces you to check the controls actually work: indicators, internal audits and management review.

Content reviewed on

Monitoring and measurement

Determine which controls need monitoring —access attempts, incidents, response times— and evaluate their effectiveness.

Internal audit

An ISMS internal audit programme with defined criteria and scope, and auditors independent of the area being audited.

Management review

Review with specific inputs: audit results, risk status, security incidents and changes in context.

What an auditor usually asks for

  • Up-to-date control effectiveness indicators
  • A completed ISMS internal audit programme
  • Management review minutes with the standard's specific inputs
  • Evidence that review decisions are carried out

How to cover performance evaluation in Kimobox

  1. 1Set up security indicators to calculate themselves from the system's records.
  2. 2Plan the ISMS internal audit programme directly on the platform.
  3. 3Prepare management review with incidents and risks already aggregated.

Security indicators stop depending on a manual report every quarter.

See audits and indicators in the quality portal

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024