Skip to content

Evidence request lists

ISO/IEC 27004:2016

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annex B: Example Measurements

27004-B.1
Example measurement definitions

Provides 35 example measurements using a typical definition structure and form

Artefacts an auditor will ask for
  • Example measurement catalog
  • Control effectiveness reports
  • Process KPI dashboard
  • Measurement template
Where this commonly fails
  • Examples not adapted
  • Effectiveness conflated with activity
  • KPIs not actionable
  • Templates ignored
27004-B.2
Control effectiveness examples

Examples of measuring the effectiveness of information security controls

Artefacts an auditor will ask for
  • Example measurement catalog
  • Control effectiveness reports
  • Process KPI dashboard
  • Measurement template
Where this commonly fails
  • Examples not adapted
  • Effectiveness conflated with activity
  • KPIs not actionable
  • Templates ignored
27004-B.3
Process performance examples

Examples of measuring the performance of ISMS processes

Artefacts an auditor will ask for
  • Example measurement catalog
  • Control effectiveness reports
  • Process KPI dashboard
  • Measurement template
Where this commonly fails
  • Examples not adapted
  • Effectiveness conflated with activity
  • KPIs not actionable
  • Templates ignored

Annex Examples

27004-A.1
Coverage Measures

Measure coverage of security controls such as percentage of assets with required controls applied.

Artefacts an auditor will ask for
  • Asset inventory
  • Control coverage reports
  • Gap lists
Where this commonly fails
  • Inventory incomplete
  • Coverage unmeasured
27004-A.2
Patching and Vulnerability Measures

Measure timeliness and completeness of patching and vulnerability remediation activities.

Artefacts an auditor will ask for
  • Patch metrics
  • Time-to-remediate reports
  • SLA evidence
Where this commonly fails
  • No SLA tracking
  • Reports stale
27004-A.3
Incident Measures

Measure number, severity, mean-time-to-detect, and mean-time-to-respond for security incidents.

Artefacts an auditor will ask for
  • Incident KPIs
  • MTTD and MTTR reports
  • Severity distributions
Where this commonly fails
  • MTTD untracked
  • Severity inconsistent
27004-A.4
Awareness and Training Measures

Measure completion rates, comprehension, and behaviour change from security awareness and training.

Artefacts an auditor will ask for
  • Completion reports
  • Phishing simulation results
  • Comprehension tests
Where this commonly fails
  • Behaviour change unmeasured
  • Phishing results not actioned
27004-A.5
Access Control Measures

Measure access review completion, orphan account counts, and privileged access activity.

Artefacts an auditor will ask for
  • Access review reports
  • Orphan account lists
  • Privileged session logs
Where this commonly fails
  • Reviews incomplete
  • Orphans not actioned
27004-A.6
Third-Party Measures

Measure third-party assessment completion, finding closure, and contractual security clause coverage.

Artefacts an auditor will ask for
  • Vendor assessment register
  • Finding tracker
  • Contract clause inventory
Where this commonly fails
  • Assessments overdue
  • Clause coverage gaps

Clause 1-4: Introductory Clauses

27004-1
Scope

Defines the scope of guidance for evaluating information security performance and ISMS effectiveness per ISO/IEC 27001:2013, 9.1

Artefacts an auditor will ask for
  • Measurement framework
  • Scope document
  • Normative references list
  • Structure overview
Where this commonly fails
  • Framework not adopted
  • References outdated
  • Scope misaligned with ISMS
  • Structure not understood
27004-2
Normative references

References to ISO/IEC 27000 and other related standards

Artefacts an auditor will ask for
  • Measurement framework
  • Scope document
  • Normative references list
  • Structure overview
Where this commonly fails
  • Framework not adopted
  • References outdated
  • Scope misaligned with ISMS
  • Structure not understood
27004-3
Terms and definitions

Definitions of measurement, monitoring, analysis, and evaluation terminology

Artefacts an auditor will ask for
  • Measurement framework
  • Scope document
  • Normative references list
  • Structure overview
Where this commonly fails
  • Framework not adopted
  • References outdated
  • Scope misaligned with ISMS
  • Structure not understood
27004-4
Structure and overview

Overview of the measurement model structure and relationship between components

Artefacts an auditor will ask for
  • Measurement framework
  • Scope document
  • Normative references list
  • Structure overview
Where this commonly fails
  • Framework not adopted
  • References outdated
  • Scope misaligned with ISMS
  • Structure not understood

Clause 5: Monitoring, Measurement, Analysis and Evaluation Rationale

27004-5.1
Need for Measurement

Define why measurement is needed to evaluate effectiveness of ISMS and supporting information security controls.

Artefacts an auditor will ask for
  • Measurement need statement
  • Stakeholder requirements
  • Business case
Where this commonly fails
  • No documented need
  • Stakeholders not consulted
27004-5.2
Fulfilling 27001 Requirements

Demonstrate how measurement programme satisfies ISO 27001 Clause 9.1 monitoring, measurement, analysis, evaluation requirements.

Artefacts an auditor will ask for
  • Mapping to 27001 Clause 9.1
  • Gap analysis
  • Programme charter
Where this commonly fails
  • No explicit mapping
  • Gaps unaddressed
27004-5.3
Validity of Results

Ensure measurement results are valid, comparable, reproducible, and useful for decision making.

Artefacts an auditor will ask for
  • Validity criteria
  • Reproducibility tests
  • Peer review records
Where this commonly fails
  • No validity check
  • Results not reproducible

Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation

27004-6.1
What to Monitor and Measure

Determine objects of measurement covering processes, controls, and the ISMS as a whole.

Artefacts an auditor will ask for
  • Measurement object inventory
  • Selection rationale
  • Approval record
Where this commonly fails
  • Objects not inventoried
  • Rationale missing
27004-6.2
Who to Monitor and Measure

Identify roles responsible for monitoring, measurement, analysis, evaluation, reporting, and review.

Artefacts an auditor will ask for
  • RACI for measurement
  • Role descriptions
  • Appointment records
Where this commonly fails
  • Roles unclear
  • No accountable owner
27004-6.3
When to Monitor and Measure

Define timing, frequency, and reporting cadence for each measurement.

Artefacts an auditor will ask for
  • Measurement calendar
  • Reporting schedule
  • Trigger criteria
Where this commonly fails
  • No calendar
  • Cadence missed
27004-6.4
How to Monitor and Measure

Define methods, formulas, scales, and tools to ensure consistent measurement collection and calculation.

Artefacts an auditor will ask for
  • Measurement constructs
  • Tool configurations
  • Calculation worksheets
Where this commonly fails
  • Methods undocumented
  • Scales inconsistent

Clause 7: Types of Measures

27004-7.1
Performance Indicators

Define performance indicators that show how well processes or controls perform.

Artefacts an auditor will ask for
  • KPI definitions
  • Targets and thresholds
  • Trend reports
Where this commonly fails
  • No thresholds
  • Targets arbitrary
27004-7.2
Effectiveness Indicators

Define indicators that show whether security controls achieve intended outcomes.

Artefacts an auditor will ask for
  • Effectiveness indicator catalogue
  • Control objective mapping
  • Outcome evidence
Where this commonly fails
  • KEIs not mapped to objectives
  • Outcomes not measured
27004-7.3
Measurement Construct

Document each measurement construct with base measures, derived measures, indicators, and decision criteria.

Artefacts an auditor will ask for
  • Construct templates
  • Base and derived measure definitions
  • Decision criteria
Where this commonly fails
  • Constructs incomplete
  • Decision criteria absent

Clause 8: Processes

27004-8.1
Data Collection

Collect measurement data using defined methods, tools, sources, and ensuring data integrity.

Artefacts an auditor will ask for
  • Source data evidence
  • Tool exports
  • Integrity controls
Where this commonly fails
  • Source data ungoverned
  • No integrity checks
27004-8.2
Analysis

Analyse measurement data to produce indicators using defined techniques and tools.

Artefacts an auditor will ask for
  • Analysis methodology
  • Tool outputs
  • Anomaly investigation
Where this commonly fails
  • No methodology
  • Anomalies ignored
27004-8.3
Evaluation of measures

Evaluate information security performance and ISMS effectiveness based on analysis results

Artefacts an auditor will ask for
  • Measurement program
  • Evaluation report
  • Process review minutes
  • Improvement actions
Where this commonly fails
  • Program not maintained
  • Evaluation skipped
  • Reviews irregular
  • Actions stalled
27004-8.4
Review and improvement of processes

Review monitoring, measurement, analysis, and evaluation processes and retain documented information

Artefacts an auditor will ask for
  • Measurement program
  • Evaluation report
  • Process review minutes
  • Improvement actions
Where this commonly fails
  • Program not maintained
  • Evaluation skipped
  • Reviews irregular
  • Actions stalled

Evaluation

27004-9.1
Evaluation of Results

Evaluate indicators against decision criteria and document conclusions about ISMS performance and effectiveness.

Artefacts an auditor will ask for
  • Evaluation reports
  • Conclusion records
  • Decisions taken
Where this commonly fails
  • No conclusions documented
  • Decisions not linked

Improvement

27004-10.1
Programme Review and Improvement

Review the measurement programme periodically and improve constructs, methods, and processes based on findings.

Artefacts an auditor will ask for
  • Programme review minutes
  • Construct updates
  • Improvement actions
Where this commonly fails
  • No periodic review
  • Constructs stale

Reporting

27004-9.2
Communication and Reporting

Communicate measurement results to relevant stakeholders in formats appropriate to their needs.

Artefacts an auditor will ask for
  • Stakeholder reports
  • Dashboards
  • Distribution evidence
Where this commonly fails
  • Reports too technical
  • Distribution informal
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.