Clause 9.1 of ISO27001:2022 requires organizations to carry out practical monitoring of their information security management system (ISMS).

In concrete terms, we defined the security objectives of our security program when we implemented Clause 6.2. Now we need to monitor them. Obtain performance indicators and compare our results with our objectives!

Here we want to measure our success, by establishing clear criteria and measurable indicators that enable us to concretely assess the progress made by our teams.

Have we achieved our objectives, or do we need to improve our safety program?

ISO27001 – Clause 9.1- Monitoring our dashboard

Target – Photo by Afif Ramdhasuma on Unsplash

Monitoring & Measurement

For a small company, I create a spreadsheet-type file, then indicate the information in columns.

  • The objective is to reduce security incidents by 20% by the end of the year.
  • Necessary resources, such as tools, licenses, or other prerequisites like specific training or safety equipment.
  • Who is responsible for collecting and analyzing the information, e.g. the security manager or a specific member of the IT team.
  • How the analysis will be carried out, for example using monthly audits, automated reports or quarterly reviews.
  • Evaluation criteria, such as green, yellow and red. Green indicates that objectives have been met, yellow indicates average results that require attention, and red indicates a significant deviation that requires immediate action.
  • The target that represents success, e.g. 95% compliance with internal security policies.

I then create an additional column for each evaluation period, such as Q1, Q2, Q3 and Q4, to track the evolution of each indicator over the year. Each quarter, the data is updated to assess progress, and corrective action is planned where necessary.

This file then represents my simplified dashboard. It provides an overview of the current state of information security within the company, making it easy to see where improvements need to be made, and ensuring that the resources allocated to the objectives are sufficient and well used.

At the end of the year, this also enables us to look back on the actions and improvements we’ve made, and to plan our objectives for the following year more effectively.

Steps

  1. Repeat the objectives defined in clause 6.2: Make sure your ISMS objectives are clear. For example, an objective could be that 95% of employees attend annual information security training.
  2. Plan the monitoring of goal attainment: When do we want to check their status? For example, monthly, quarterly?
  3. Define success criteria: I like to use a color system, with green representing success, yellow representing a level that’s under surveillance but acceptable, and red representing a situation that needs to be corrected quickly. For example, what level of delay in updates is acceptable? Is a one-month delay tolerable?
  4. Determine the means and tools to be used to obtain the indicators: What tools will be put in place to collect the necessary information?
  5. Take corrective measures if necessary: Don’t forget to document corrective measures if a situation reaches red level and requires action.

Advice

  • Involve stakeholders in defining performance targets and KPIs.
  • Use monitoring and measurement tools tailored to your organization’s needs.
  • Communicate monitoring and evaluation results to stakeholders.
  • Continuously improve the monitoring and evaluation process.

Success Criteria

To determine whether you have met clause 9.1 of ISO27001:2022, here are some questions an auditor might ask:

  • What are the objectives of your ISMS, and how do they relate to the organization’s overall objectives?
  • What key performance indicators (KPIs) do you use to measure the effectiveness of your ISMS?
  • How do you monitor and measure information security incidents?
  • Describe a recent example where you took corrective action following an analysis?
  • Where are the results of monitoring activities documented?

By complying with the requirements of clause 9.1, you will not only contribute to the effectiveness of the ISMS, but also to the continuous improvement of information security within the organization.