ISO/IEC 27004:2016
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Annex B: Example Measurements
Provides 35 example measurements using a typical definition structure and form
- Example measurement catalog
- Control effectiveness reports
- Process KPI dashboard
- Measurement template
- Examples not adapted
- Effectiveness conflated with activity
- KPIs not actionable
- Templates ignored
Examples of measuring the effectiveness of information security controls
- Example measurement catalog
- Control effectiveness reports
- Process KPI dashboard
- Measurement template
- Examples not adapted
- Effectiveness conflated with activity
- KPIs not actionable
- Templates ignored
Examples of measuring the performance of ISMS processes
- Example measurement catalog
- Control effectiveness reports
- Process KPI dashboard
- Measurement template
- Examples not adapted
- Effectiveness conflated with activity
- KPIs not actionable
- Templates ignored
Annex Examples
Measure coverage of security controls such as percentage of assets with required controls applied.
- Asset inventory
- Control coverage reports
- Gap lists
- Inventory incomplete
- Coverage unmeasured
Measure timeliness and completeness of patching and vulnerability remediation activities.
- Patch metrics
- Time-to-remediate reports
- SLA evidence
- No SLA tracking
- Reports stale
Measure number, severity, mean-time-to-detect, and mean-time-to-respond for security incidents.
- Incident KPIs
- MTTD and MTTR reports
- Severity distributions
- MTTD untracked
- Severity inconsistent
Measure completion rates, comprehension, and behaviour change from security awareness and training.
- Completion reports
- Phishing simulation results
- Comprehension tests
- Behaviour change unmeasured
- Phishing results not actioned
Measure access review completion, orphan account counts, and privileged access activity.
- Access review reports
- Orphan account lists
- Privileged session logs
- Reviews incomplete
- Orphans not actioned
Measure third-party assessment completion, finding closure, and contractual security clause coverage.
- Vendor assessment register
- Finding tracker
- Contract clause inventory
- Assessments overdue
- Clause coverage gaps
Clause 1-4: Introductory Clauses
Defines the scope of guidance for evaluating information security performance and ISMS effectiveness per ISO/IEC 27001:2013, 9.1
- Measurement framework
- Scope document
- Normative references list
- Structure overview
- Framework not adopted
- References outdated
- Scope misaligned with ISMS
- Structure not understood
References to ISO/IEC 27000 and other related standards
- Measurement framework
- Scope document
- Normative references list
- Structure overview
- Framework not adopted
- References outdated
- Scope misaligned with ISMS
- Structure not understood
Definitions of measurement, monitoring, analysis, and evaluation terminology
- Measurement framework
- Scope document
- Normative references list
- Structure overview
- Framework not adopted
- References outdated
- Scope misaligned with ISMS
- Structure not understood
Overview of the measurement model structure and relationship between components
- Measurement framework
- Scope document
- Normative references list
- Structure overview
- Framework not adopted
- References outdated
- Scope misaligned with ISMS
- Structure not understood
Clause 5: Monitoring, Measurement, Analysis and Evaluation Rationale
Define why measurement is needed to evaluate effectiveness of ISMS and supporting information security controls.
- Measurement need statement
- Stakeholder requirements
- Business case
- No documented need
- Stakeholders not consulted
Demonstrate how measurement programme satisfies ISO 27001 Clause 9.1 monitoring, measurement, analysis, evaluation requirements.
- Mapping to 27001 Clause 9.1
- Gap analysis
- Programme charter
- No explicit mapping
- Gaps unaddressed
Ensure measurement results are valid, comparable, reproducible, and useful for decision making.
- Validity criteria
- Reproducibility tests
- Peer review records
- No validity check
- Results not reproducible
Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation
Determine objects of measurement covering processes, controls, and the ISMS as a whole.
- Measurement object inventory
- Selection rationale
- Approval record
- Objects not inventoried
- Rationale missing
Identify roles responsible for monitoring, measurement, analysis, evaluation, reporting, and review.
- RACI for measurement
- Role descriptions
- Appointment records
- Roles unclear
- No accountable owner
Define timing, frequency, and reporting cadence for each measurement.
- Measurement calendar
- Reporting schedule
- Trigger criteria
- No calendar
- Cadence missed
Define methods, formulas, scales, and tools to ensure consistent measurement collection and calculation.
- Measurement constructs
- Tool configurations
- Calculation worksheets
- Methods undocumented
- Scales inconsistent
Clause 7: Types of Measures
Define performance indicators that show how well processes or controls perform.
- KPI definitions
- Targets and thresholds
- Trend reports
- No thresholds
- Targets arbitrary
Define indicators that show whether security controls achieve intended outcomes.
- Effectiveness indicator catalogue
- Control objective mapping
- Outcome evidence
- KEIs not mapped to objectives
- Outcomes not measured
Document each measurement construct with base measures, derived measures, indicators, and decision criteria.
- Construct templates
- Base and derived measure definitions
- Decision criteria
- Constructs incomplete
- Decision criteria absent
Clause 8: Processes
Collect measurement data using defined methods, tools, sources, and ensuring data integrity.
- Source data evidence
- Tool exports
- Integrity controls
- Source data ungoverned
- No integrity checks
Analyse measurement data to produce indicators using defined techniques and tools.
- Analysis methodology
- Tool outputs
- Anomaly investigation
- No methodology
- Anomalies ignored
Evaluate information security performance and ISMS effectiveness based on analysis results
- Measurement program
- Evaluation report
- Process review minutes
- Improvement actions
- Program not maintained
- Evaluation skipped
- Reviews irregular
- Actions stalled
Review monitoring, measurement, analysis, and evaluation processes and retain documented information
- Measurement program
- Evaluation report
- Process review minutes
- Improvement actions
- Program not maintained
- Evaluation skipped
- Reviews irregular
- Actions stalled
Evaluation
Evaluate indicators against decision criteria and document conclusions about ISMS performance and effectiveness.
- Evaluation reports
- Conclusion records
- Decisions taken
- No conclusions documented
- Decisions not linked
Improvement
Review the measurement programme periodically and improve constructs, methods, and processes based on findings.
- Programme review minutes
- Construct updates
- Improvement actions
- No periodic review
- Constructs stale
Reporting
Communicate measurement results to relevant stakeholders in formats appropriate to their needs.
- Stakeholder reports
- Dashboards
- Distribution evidence
- Reports too technical
- Distribution informal
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.