Performance Evaluation for ISO 27001 Information Security
ISO 27001 Clause 9
This clause requires the organisation to monitor ISMS performance, conduct internal audits and complete management reviews to confirm continuing suitability and effectiveness.
ISO 27001 Clause 9 - Performance Evaluation
Clause 9 is where the management system checks itself. After the planning of Clause 6 and the operational delivery of Clause 8, Clause 9 asks how well it is all working. The clause covers three main activities - measuring the performance of the controls and the system, auditing whether the system is doing what it says it does, and reviewing the system at top management level.
Sub-clauses of ISO 27001 Clause 9
Clause 9.1 - Monitoring, Measurement, Analysis and Evaluation requires the organisation to determine what needs to be monitored and measured, the methods used, when it happens, who does it and how the results are analysed and evaluated.
Clause 9.2 - Internal Audit requires the organisation to conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the standard and the organisation's own requirements and is effectively implemented and maintained.
Clause 9.3 - Management Review requires top management to review the ISMS at planned intervals, with specific inputs to be considered and specific outputs to be produced.
