ISO 27001:2022 Clause 9.1 Monitoring, Measurement, Analysis, Evaluation Explained

In this guide you will learn how to implement ISO 27001:2022 Clause 9.1 Monitoring, Measurement, Analysis, Evaluation and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

Key Takeaways

ISO 27001 Clause 9.1 requires organizations to evaluate the information security performance and the effectiveness of the Information Security Management System (ISMS). This is the “Check” in the PDCA cycle. You cannot simply implement controls and hope for the best; you must actively monitor their performance using valid, reproducible metrics. The goal is to move from “feeling secure” to “proving security” through hard data.

What Is ISO 27001 Clause 9.1?

ISO 27001 Clause 9.1 Monitoring, Measurement, Analysis, Evaluation requires an organisation to implement measures and monitors to evaluate the effectiveness of the information security management system. It is a requirement to maintain evidence of the results of measures and monitors.

Definition

The ISO 27001 standard defines ISO 27001 Monitoring, Measurement, Analysis, Evaluation as:

The organisation shall determine:
a) what needs to be monitored and measured, including information security processes and controls;
b) the methods for monitoring, measurement, analysis and evaluation, as applicable, to ensure valid results. The methods selected should produce comparable and reproducible results to be considered valid.
c) when the monitoring and measuring shall be performed;
d) who shall monitor and measure;
e) when the results from monitoring and measurement shall be analysed and evaluated;
f) who shall analyse and evaluate these results.
Documented information shall be available as evidence of the results.
The organisation shall evaluate the information security performance and effectiveness of the information security management system.

ISO27001:2022 Clause 9.1 Monitoring, Measurement, analysis, evaluation

FREE ISO 27001 Clause 9.1 Training Video

How to Implement ISO 27001 Clause 9.1

Implementation Guide

You demonstrate compliance to ISO 27001 Clause 9.1 by having in place measures and monitors that you can show to an auditor and evidence of the operation of those measures and monitors with historical reports that show historic results.

Document your systems and processes

To understand what needs to be measured and monitored you must know what you have. Document your systems and processes. System architecture diagrams, network diagrams, server and virtual server layout diagrams, technology stacks, physical asset register and data asset register are examples of good, best practice documentation that will enable you to implement effective measures and monitors.

Conduct a risk assessment

Follow your risk management methodology and conduct a risk assessment on the assets that make up your products and services. This will allow you to prioritise your resources and identify they key systems that require monitoring.

Decide what to monitor

Looking at the functionality of the process and systems and using the diagrams and risk assessment decide exactly what it is that you are going to monitor. It is often not feasible to monitor everything. Make sure you are monitoring what is important and of risk.

Decide what to measure

The measures that make up the monitors should be decided. Exactly what are you going to measure, technically. This will be based on the technology that you have deployed and it’s inbuilt capabilities as well as a review of third party tools that may be required to plug any gaps.

Create a measures report

Reporting should be conducted at several levels. You will have automatic alerts on that feed into your various processes such as incident management as well as creating snap shot reports to satisfy the various needs of stakeholders in your organisation. You will maintain evidence of these reports.

Implement regular reviews

It is no point in having measures and monitors if they are not reviewed. Some tools have the capability to issue realtime alerts. It is also good practice to set aside time on a regular basis to preform manual reviews of the all of the data points that you are collecting. This includes a pass over of the automated alerts to ensure that none have been missed, they are configured correctly and being responded to correctly.

Implement exception steps

Exception steps are important as they define what happens when a measure or monitor hits a particular threshold. Implement steps that cover what happens if the measures and monitors fail, or exceed defined thresholds.

Regularly report the Management Review Team

It is a requirement to share the out put of the measure and monitors with the management review team as part of the process of continual improvement and oversight. Results should be shared and talked through as well as any required corrective actions.

Follow the continual improvement process

Measures and monitors will continually evolve so be sure to follow the continual improvement processes. Threat intelligence will lead to changes to what you monitor and how you respond.

Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

Further Guidance

There is further guidance provided in the ISO 27001 Annex A Controls that was revised in 2022 with changes to the ISO 27002 standard and specifically calls out required monitoring and analysis. As you would expect this a fundamental area for an information security management system and as such it touches most of the controls. Here will look at some actual specifics and take a look at what Annex A says.

There are many ways to implement measures and monitors and what is right for you will depend on your company culture and the tools available.

Consider the best methods for you that you know get results and where possible retain evidence of your measures and monitors.

Technical tools are great but also consider the manual reviews, checks and balances and consider for the manual processes how you will record them and evidence them.

Threat Intelligence

This is a new control introduced in 2022. Whilst not a direct measure and monitor it is an indirect measure and monitor that allows an organisation to gather threat intelligence to more effectively understand risk, what controls may be required and better protect itself.

Information relating to information security threats should be collected and analysed to produce threat intelligence.

ISO 27001:2022 Annex A 5.7 Threat Intelligence

Logging

Logging is one of the more straight forward measures and monitors that we can introduce and is often provided as a default capability of most applications and systems.

Logs that record activities, exceptions, faults and other relevant events should be produced, stored, protected and analysed.

ISO 27001:2022 Annex A 8.15 Logging

Monitoring, review and change management of supplier services

Supply chain security represents one of the biggest risks to any organisation as it is something that is outside your direct control. Ensuring a regular review and monitoring of their security practices and service delivery seeks to gain assurance that they are doing the right thing for information security and therefore protecting you, your customers and your clients.

The organisation should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.

ISO 27001 Annex A 5.22 Monitoring, review and change management of supplier services

Physical security monitoring

The requirements of ISO 27002 clause 7.5 are satisfied by physical controls such as locked doors, person controlled reception areas, visitor cards, escorted visitors, potentially CCTV cameras and alarms. This is traditional security around access to physical locations.

Premises should be continuously monitored for unauthorised physical access.

ISO 27001:2022 Annex A 7.5 Physical security monitoring

Capacity Management

Monitoring, reporting, analysing and responding to capacity management is specifically aimed at the availability aspect of information security. Ensuring that information and systems are available when required and negating any unintended consequences of exceeding the capacity capabilities of those systems.

The use of resources should be monitored and adjusted in line with current and expected capacity requirements.

ISO 27001:2022 Annex A 8.6 Capacity Management

Configuration Management

Configurations, including security configurations, of hardware, software, services and networks should be established, documented, implemented, monitored and reviewed.

ISO 27001:2022 Annex A 8.9 Configuration Management

Logging

Similar to the next clause, 8.16 monitoring actives, this clause on logging is a bit of a catch all clause.

Logs that record activities, exceptions, faults and other relevant events should be produced, stored, protected and analysed.

ISO 27001:2022 Annex A 8.15 Logging

Monitoring Activities

We have seen some specific requirements on measures and monitors but now we enter what we call a ‘catch all’ clause that basically says monitor everything. There is an art and a science in actually deciding and justifying what you monitor so as not to have monitoring overload.

Networks, systems and applications should be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.

ISO 27001:2022 Annex A 8.16 Monitoring Activities

Security of Network Services

Security mechanisms, service levels and service requirements of network services should be identified, implemented and monitored.

ISO 27001:2022 Annex A 8.21 Security of Network Services

Outsourced Development

This is one of the few clauses in the statement of applicability that is often not applicable, especially if you do not outsource your software development or do software development. If you do then monitoring and review is required.

The organisation should direct, monitor and review the activities related to outsourced system development.

ISO 27001:2022 Annex A 8.30 Outsourced Development

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Clause 9.1 FAQ

What is ISO 27001 Clause 9.1 Monitoring, Measurement, analysis, evaluation?

ISO 27001 Clause 9.1 Monitoring, Measurement, analysis, evaluation requires and organisation to implement measures and monitors to evaluate the effectiveness of the information security management system. It is a requirement to maintain evidence of the results of measures and monitors.

How do I evidence I meet the requirement of ISO 27001 Clause 9.1?

You demonstrate compliance to ISO 27001 Clause 9.1 by having in place measures and monitors that you can show to an auditor and evidence of the operation of those measures and monitors with historical reports that show historic results.

Where can I download ISO 27001 Clause 9.1 templates?

You can download ISO 27001 Clause 9.1 templates in the ISO 27001 Toolkit.

ISO 27001 Clause 9.1 example?

An example of ISO 27001 Clause 9.1 can be found in the ISO 27001 Toolkit.

What is an ISO 27001 measure for clause 9.1?

A measure is something that can be observed to happen that has a quantitive value.

What is an ISO 27001 monitor for clause 9.1?

A monitor is the system by which the measures are collected and recorded.

What is the difference between ISO 27001 measures and ISO 27001 monitors?

Monitors are the systems by which the measures are captured. A monitor is an oversight or observation where as a measure is an actual value or metric.

How do you comply with ISO 27001 clause 9.1?

You comply with ISO 27001 clause 9.1 by identifying which measures and monitors you need based on risk and business need and then implementing them. In addition you implement the processes to oversee and react to them and you implement effective reporting for governance and oversight. Finally you implement continual improvement and incident management processes to handle the out put of the processes.

What is an example of an ISO 27001 measure for ISO 27001 clause 9.1?

An example measure for ISO 27001 clause 9.1 would be the number of machines with active anti virus, the number of machines patched, the number of people trained.

What is an example of an ISO 27001 monitor for ISO 27001 clause 9.1?

An example monitor for ISO 27001 clause 9.1 would be to have anti virus in place with auto alerts and reporting enabled, to have asset management software in place than handles patching and reports on failed patching attempts, to have a report that periodically shows the number of people that are not trained in information security.

Who does the analysis of ISO 27001 measures and monitors?

The analysis of ISO 27001 measure and monitors is performed by the allocated system and process owner. They are best placed to understand the results and provide guidance based on those results.

How often do you review and analyse ISO 27001 measures and monitors?

As often as is necessary based on risk. It would not be unreasonable for the review to be conducted monthly.

How long do I keep results of ISO 27001 measures and monitors?

For as long as is necessary based on business need and risk. It would not be unreasonable to keep the results for a rolling period of 18 months.

Who do I share ISO 27001 measures and monitors with?

You share the results with the owner of the thing, process, system that is being measured and monitored. In addition you share it with the Management Review Team as part of the process of continual improvement for oversight and signify.

I identified a problem in my ISO 27001 measures and monitors, what do I do now?

Follow your process of continual improvement and make the necessary changes to the measure and monitor.

ISO 27001 Management Review: Clause 9.3

Further Reading

ISO 27001 Logging and Monitoring Policy Template

ISO 27001 Monitoring, Measurement, Analysis and Evaluation | Beginner’s Guide

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top