Clause 9

Performance evaluation

Check it works: monitor and measure, run internal audits, and hold management reviews.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILClause 9 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Mandatory documents in this clause

  • Monitoring and measurement results (9.1)
  • Internal audit programme and results (9.2)
  • Management review results (9.3)
9.1

Monitoring, measurement, analysis and evaluation

What it requires: Determine what to monitor and measure, the methods, when, and by whom, then analyse and evaluate the results to assess information security performance and ISMS effectiveness. Keep documented evidence.

How to meet it: Define a small set of security metrics and review them on a schedule.

9.2

Internal audit

What it requires: Conduct internal audits at planned intervals to confirm the ISMS conforms to your own requirements and the standard and is effectively implemented. Run an audit programme (frequency, methods, responsibilities, reporting), use objective and impartial auditors, and report results to management.

How to meet it: Maintain an audit programme; have someone independent of the area audit it and report findings.

9.3

Management review

What it requires: Top management must review the ISMS at planned intervals, considering prior actions, changes in issues and interested parties, performance feedback (nonconformities, monitoring, audits, objectives), interested-party feedback, risk assessment and treatment status, and improvement opportunities. Results must include decisions on improvements and any ISMS changes.

How to meet it: Hold a recurring management review (at least annually) and keep minutes capturing the inputs and decisions.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Looking for the Annex A controls? See all 93 controls. To run these requirements with automation, read how AI manages compliance.