ISO 27001 provides no guidance and is of little help
In deciding what to monitor and measure regarding your Information Security Management System (ISMS), ISO 27001 specifies no mandatory requirements (as emphasized in our ISO 27001 training courses). Thankfully, ISO 27004 provides guidelines and principles for measuring and reporting the effectiveness of an organization's ISMS. The standard helps organizations to evaluate information security management processes, identify weaknesses, and take corrective actions.
This article will explore ISO 27004 and the importance of measuring information security effectiveness.
What is ISO/IEC 27004:2016?
Importance of Measuring Information Security Effectiveness
Mapping ISO 27001:2022 vs. ISO 27004:2016
How to measure information security effectiveness?
Now it's your turn!
Related Courses
Related Articles
- How does ISO 27001:2022 Compare with ISO 27001:2013?
- ISO 27001 Implementation in 31 Steps (downloadable PDF file attached)
- Free ISO 27001 Implementation Handbook (100+ pages)
deGRANDSON Global is an ISO Certified Educational Organization
In
October 2021, we secured certification to three education-related ISO Standards. As a result, we now have a university-grade management system in place conforming to the requirements of …
We have chosen ISO 21001 certification because, unlike IRCA and Exemplar badges (which, in our opinion, are commercially compromised), it is based on independent third-party assessment. In addition, it is a ‘university grade’ standard in use globally by schools, colleges, and universities to demonstrate their competence.
We provide Courses for ISO 9001, ISO 13485, ISO 14001, ISO 17025, ISO 27001, ISO 45001, Risk Management, GDPR, and more.
Related Courses
Written by Dr John FitzGerald
Related Articles…
ISO 27001 offers a comprehensive framework that can incorporate all information security regulations and schemes - GDPR, HIPAA, SOC 2, CCPA, etc. Information security/cybersecurity has become crucial to any organization's functioning in today's digital age. With the increasing amount of data and sensitive information being stored and ... Continue reading
In 2018, many organizations, not only those based in the EU, spent much time and money on compliance with the General Data Protection Regulation (GDPR). But what actions should we take now to ensure ongoing compliance? It's not enough to have policies and procedures to demonstrate that you comply with the requirements. If there is a data ... Continue reading