Monitoring, Measurement, Internal Audit and Management Review
Clause 9 (Performance Evaluation) of ISO/IEC 27001:2022 requires the organization to verify that its Information Security Management System (ISMS) works as intended and achieves its intended outcomes. It contains three linked requirements. Monitoring, measurement, analysis and evaluation (9.1): The… Clause 9 (Performance Evaluation) of ISO/IEC 27001:2022 requires the organization to verify that its Information Security Management System (ISMS) works as intended and achieves its intended outcomes. It contains three linked requirements. Monitoring, measurement, analysis and evaluation (9.1): The organization must determine what needs to be monitored and measured, including information security processes and controls. It must also define the methods used, which should produce comparable and reproducible results, when monitoring and measuring occur and who performs them, and when and by whom results are analysed and evaluated. Documented information must be available as evidence of the results. Auditors look for meaningful metrics tied to information security objectives, such as incident trends, patch compliance or awareness training completion, rather than data collected for its own sake. Internal audit (9.2): Audits must be conducted at planned intervals to determine whether the ISMS conforms to the organization's own requirements and to ISO/IEC 27001, and whether it is effectively implemented and maintained. The organization must plan, establish, implement and maintain an audit programme that considers the importance of the processes concerned and the results of previous audits. For each audit, criteria and scope must be defined and auditors selected to ensure objectivity and impartiality. Results must be reported to relevant management, and documented information must be retained as evidence of the programme and its results. ISO 19011 provides guidance on auditing. Management review (9.3): Top management must review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Inputs include the status of previous actions, changes in internal and external issues, and changes in interested parties' needs and expectations. They also include feedback on security performance, covering nonconformities, corrective actions, measurement results, audit findings and achievement of objectives. Further inputs are risk assessment results, the status of risk treatment, and opportunities for improvement. Outputs include decisions on improvements and any needed changes to the ISMS, retained as documented information. Together, these activities feed Clause 10 (Improvement) and complete the Plan-Do-Check-Act cycle.
Monitoring, Measurement, Internal Audit and Management Review (ISO/IEC 27001 Clause 9: Performance Evaluation)
Introduction
Clause 9 of ISO/IEC 27001:2022, Performance Evaluation, is the 'Check' stage of the Plan-Do-Check-Act (PDCA) cycle. It has three parts:
1. Clause 9.1: Monitoring, measurement, analysis and evaluation
2. Clause 9.2: Internal audit (in 2022 split into 9.2.1 General and 9.2.2 Internal audit programme)
3. Clause 9.3: Management review (in 2022 split into 9.3.1 General, 9.3.2 Management review inputs and 9.3.3 Management review results)
For an ISO 27001 Lead Auditor, Clause 9 is one of the most heavily tested areas. It shows whether the organization knows how its ISMS is performing, rather than assuming it works.
Why It Is Important
1. Evidence-based assurance: Without monitoring and measurement, an organization cannot show that its information security controls are effective. Clause 9 turns 'we think it works' into 'we have evidence it works'.
2. Drives continual improvement: The outputs of Clause 9 feed Clause 10 (Improvement). Nonconformities found by audits and decisions made in management review lead to corrective actions and improvement.
3. Top management accountability: Management review keeps leadership engaged (see Clause 5, Leadership). It confirms the ISMS remains suitable, adequate and effective.
4. Certification requirement: Certification bodies will not grant initial certification unless at least one full cycle of internal audits and a management review has been completed. A missing internal audit or management review usually results in a major nonconformity.
5. Independent verification: Internal audits give an objective view of conformity. They check against both the organization's own requirements and the requirements of ISO/IEC 27001.
6. Risk-based alignment: Measurement confirms whether risk treatment is working and whether information security objectives (Clause 6.2) are being achieved.
What It Is: Clause 9.1 Monitoring, Measurement, Analysis and Evaluation
The organization must evaluate both the information security performance and the effectiveness of the ISMS. To do this, it must determine:
a) What needs to be monitored and measured, including information security processes and controls
b) The methods for monitoring, measurement, analysis and evaluation, so that results are valid. Results must be comparable and reproducible.
c) When the monitoring and measuring shall be performed
d) Who shall monitor and measure
e) When the results shall be analysed and evaluated
f) Who shall analyse and evaluate these results
Documented information must be available as evidence of the results.
Key distinctions:
- Monitoring: determining the status of a system, process or activity (observing over time)
- Measurement: a process to determine a value
- Analysis: examining the data to find trends and meaning
- Evaluation: judging the results against criteria to reach conclusions
Examples of metrics:
- Percentage of staff completing security awareness training
- Mean time to detect or respond to incidents
- Patch compliance rate
- Number of unauthorized access attempts
- Percentage of backups successfully tested
- Achievement of information security objectives
ISO/IEC 27004 gives guidance on information security measurement. It is guidance only, not a set of requirements.
What It Is: Clause 9.2 Internal Audit
The organization must conduct internal audits at planned intervals. The audits provide information on whether the ISMS:
a) Conforms to the organization's own requirements for its ISMS
b) Conforms to the requirements of ISO/IEC 27001
c) Is effectively implemented and maintained
The internal audit programme (9.2.2) must cover:
- Frequency, methods, responsibilities, planning requirements and reporting
- The importance of the processes concerned and the results of previous audits, which should be considered when establishing the programme
- Audit criteria and scope for each audit
- Selection of auditors and conduct of audits that ensure objectivity and impartiality
- Reporting of results to relevant management
- Documented information as evidence of the implementation of the audit programme and the audit results
Important nuances:
- Auditors must be objective and impartial. Auditors should not audit their own work. Full independence (for example, an external party) is NOT required.
- Internal audits can be outsourced, but responsibility remains with the organization.
- The programme need not cover every clause in one audit. However, it must cover the entire ISMS scope over the audit cycle, typically the three-year certification cycle. Many organizations aim for annual coverage.
- ISO 19011 provides guidance on auditing management systems.
- ISO/IEC 27007 gives ISMS-specific audit guidance. ISO/IEC TS 27008 covers the assessment of information security controls.
What It Is: Clause 9.3 Management Review
Top management must review the ISMS at planned intervals. The purpose is to ensure its continuing suitability, adequacy and effectiveness.
Required inputs (9.3.2):
a) Status of actions from previous management reviews
b) Changes in external and internal issues relevant to the ISMS
c) Changes in the needs and expectations of interested parties relevant to the ISMS (new in 2022)
d) Feedback on information security performance, including trends in:
- Nonconformities and corrective actions
- Monitoring and measurement results
- Audit results
- Fulfilment of information security objectives
e) Feedback from interested parties
f) Results of risk assessment and status of the risk treatment plan
g) Opportunities for continual improvement
Required outputs (9.3.3):
- Decisions related to continual improvement opportunities
- Any needs for changes to the ISMS
Documented information must be available as evidence of the results of management reviews.
How It Works in Practice
1. Define metrics: Link them to information security objectives (6.2), risks (6.1), and controls (Statement of Applicability).
2. Collect data: Use logs, SIEM, dashboards, KPIs, incident registers and training records.
3. Analyse and evaluate: Look for trends and compare results against targets and thresholds.
4. Plan the audit programme: Base it on risk, process importance and previous results.
5. Conduct internal audits: Prepare a plan, audit against criteria, gather objective evidence, report findings and follow up.
6. Feed results into management review: Top management reviews all required inputs, makes decisions and allocates resources.
7. Act (Clause 10): Carry out corrective actions on nonconformities and continual improvement, then return to Plan.
This creates a closed loop: Measure → Audit → Review → Improve.
Typical Audit Evidence a Lead Auditor Looks For
- A defined measurement framework or KPI register showing what, how, when, who measures and who evaluates
- Measurement results and trend analysis, with evidence that they were evaluated rather than just collected
- An internal audit programme covering the full scope, with a risk-based rationale
- Audit plans, checklists, reports and nonconformity records with follow-up
- Auditor competence records and evidence of impartiality
- Management review minutes showing ALL required inputs and the outputs (decisions and changes)
- Evidence that top management actually participated, not just the ISMS manager
- Action tracking from previous reviews
Common Nonconformities
- Metrics defined but never analysed or evaluated
- Metrics that only measure activity (for example, 'number of policies') rather than effectiveness
- No internal audit conducted before the certification audit (major)
- Internal auditor auditing their own area (lack of objectivity)
- The audit programme does not cover Annex A controls or parts of the scope
- Previous audit results not considered in audit planning
- Management review missing inputs, such as changes in interested parties or risk treatment status
- Management review without top management attendance
- No documented outputs or decisions from management review
- Actions from previous reviews not followed up
Exam Tips: Answering Questions on Monitoring, Measurement, Internal Audit and Management Review
1. Know the clause numbers precisely: 9.1 = monitoring and measurement, 9.2 = internal audit, 9.3 = management review. Scenario questions often ask you to cite the correct clause for a nonconformity.
2. Remember the 'what, how, when, who' list in 9.1: If a scenario says metrics exist but nobody analyses them, the nonconformity is against 9.1, specifically the determination of when and who analyses and evaluates. Results must be comparable and reproducible.
3. Objectivity and impartiality, not independence: A common trap is answers claiming internal auditors must be external or fully independent. The standard requires only objectivity and impartiality. Staff from another department can audit.
4. Two kinds of conformity in internal audit: Conformity to the organization's own requirements AND to ISO/IEC 27001. Effective implementation and maintenance must also be checked.
5. Management review = top management: If the review is done only by the IT manager or CISO without top management, it is a nonconformity against 9.3.1.
6. Memorize the management review inputs: Exams often present minutes that lack one input (for example, changes in needs and expectations of interested parties, or risk treatment plan status). Identify the missing one.
7. Outputs are decisions: These are continual improvement opportunities and needs for change. Minutes listing only information presented, with no decisions, are deficient.
8. Documented information is required for all three: Evidence of monitoring results, the audit programme and results, and management review results. Absence of records is a nonconformity.
9. Planned intervals: The standard does not mandate annual frequency. Organizations choose the interval, but it must be planned and justified. Do not pick answers stating 'ISO 27001 requires annual audits'. Note that certification bodies normally expect at least annual coverage before surveillance audits.
10. Major vs minor grading: No internal audit or management review at all, or a systemic failure, is a major. An isolated lapse, such as one missing input or one late audit, is usually a minor.
11. Link to other clauses: Objectives (6.2), risk treatment (6.1.3, 8.3), corrective action (10.2), and continual improvement (10.1). When asked 'what happens next' after an audit finding, think Clause 10.
12. Distinguish internal audit from certification audit: Internal audits are first-party. Certification audits are third-party. Audits of suppliers are second-party.
13. Stage 1 readiness: In scenario questions on audit readiness, verify that the internal audit and management review were completed before Stage 2.
14. Read the scenario for evidence words: Phrases such as 'no records', 'not analysed', 'self-audited', 'CEO absent' or 'no follow-up' point directly at specific requirements.
15. Write nonconformity statements properly: Include the requirement (clause), the evidence observed and the nonconformity statement. For example: 'Clause 9.2.2 requires auditors to be selected to ensure objectivity. Contrary to this, the access control process was audited by the access control process owner.'
16. Effectiveness, not just activity: Strong answers emphasize that measurement should show effectiveness of controls, not merely that tasks were performed.
Summary
Clause 9 provides the evidence that the ISMS works. Monitoring and measurement give data. Internal audit gives objective verification. Management review gives leadership decisions. Together they feed Clause 10 for improvement. For exams, know the specific requirements, recognize the common gaps, cite the correct clauses, and grade findings sensibly.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!