
ISO 27001 provides no guidance and is of little help
In deciding what to monitor and measure regarding your Information Security Management System (ISMS), ISO 27001 specifies no mandatory requirements (as emphasized in our ISO 27001 training courses). Thankfully, ISO 27004 provides guidelines and principles for measuring and reporting the effectiveness of an organization's ISMS. The standard helps organizations to evaluate information security management processes, identify weaknesses, and take corrective actions.
This article will explore ISO 27004 and the importance of measuring information security effectiveness.
What is ISO/IEC 27004:2016?
Importance of Measuring Information Security Effectiveness
Mapping ISO 27001:2022 vs. ISO 27004:2016
How to measure information security effectiveness?
Now it's your turn!
Related Courses
Related Articles
- How does ISO 27001:2022 Compare with ISO 27001:2013?
- ISO 27001 Implementation in 31 Steps (downloadable PDF file attached)
- Free ISO 27001 Implementation Handbook (100+ pages)
deGRANDSON Global is an ISO Certified Educational Organization
In
October 2021, we secured certification to three education-related ISO Standards. As a result, we now have a university-grade management system in place conforming to the requirements of …
We have chosen ISO 21001 certification because, unlike IRCA and Exemplar badges (which, in our opinion, are commercially compromised), it is based on independent third-party assessment. In addition, it is a ‘university grade’ standard in use globally by schools, colleges, and universities to demonstrate their competence.
We provide Courses for ISO 9001, ISO 13485, ISO 14001, ISO 17025, ISO 27001, ISO 45001, Risk Management, GDPR, and more.
Related Courses
Related Courses
Written by Dr John FitzGerald
Related Articles…
Did you know that cybersecurity is addressed in ISO 13485:2016, Clause 7.3? Whether you are marketing a Medical Device Software (MDSW) product or a medical device where software drives or influences the device, you face cybersecurity issues. In EU-regulated countries, the AI Act is a factor to consider; however, as it has been deferred ... Continue reading
Securing certification to this Information Security standard requires a collective effort. Implementing ISO 27001, the international standard for Information Security Management Systems (ISMS), can be complex, and several common errors may need to be corrected during the implementation process. Frequently Encountered Errors when ... Continue reading






