Monitoring and measurement
Determine which controls need monitoring —access attempts, incidents, response times— and evaluate their effectiveness.
Internal audit
An ISMS internal audit programme with defined criteria and scope, and auditors independent of the area being audited.
Management review
Review with specific inputs: audit results, risk status, security incidents and changes in context.
What an auditor usually asks for
- Up-to-date control effectiveness indicators
- A completed ISMS internal audit programme
- Management review minutes with the standard's specific inputs
- Evidence that review decisions are carried out
How to cover performance evaluation in Kimobox
- 1Set up security indicators to calculate themselves from the system's records.
- 2Plan the ISMS internal audit programme directly on the platform.
- 3Prepare management review with incidents and risks already aggregated.
Security indicators stop depending on a manual report every quarter.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024