Performance evaluation
Check it works: monitor and measure, run internal audits, and hold management reviews.
Mandatory documents in this clause
- ✓Monitoring and measurement results (9.1)
- ✓Internal audit programme and results (9.2)
- ✓Management review results (9.3)
Monitoring, measurement, analysis and evaluation
What it requires: Determine what to monitor and measure, the methods, when, and by whom, then analyse and evaluate the results to assess information security performance and ISMS effectiveness. Keep documented evidence.
How to meet it: Define a small set of security metrics and review them on a schedule.
Internal audit
What it requires: Conduct internal audits at planned intervals to confirm the ISMS conforms to your own requirements and the standard and is effectively implemented. Run an audit programme (frequency, methods, responsibilities, reporting), use objective and impartial auditors, and report results to management.
How to meet it: Maintain an audit programme; have someone independent of the area audit it and report findings.
Management review
What it requires: Top management must review the ISMS at planned intervals, considering prior actions, changes in issues and interested parties, performance feedback (nonconformities, monitoring, audits, objectives), interested-party feedback, risk assessment and treatment status, and improvement opportunities. Results must include decisions on improvements and any ISMS changes.
How to meet it: Hold a recurring management review (at least annually) and keep minutes capturing the inputs and decisions.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.