Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation
|Publication Date:||15 December 2016|
|ICS Code (Management systems):||03.100.70|
|ICS Code (IT Security):||35.030|
This document provides guidelines intended to assist organizations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes:
a) the monitoring and measurement of information security performance;
b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls;
c) the analysis and evaluation of the results of monitoring and measurement.
This document is applicable to all types and sizes of organizations.