ISO 27001 Clause 9.1: Monitoring, Measurement, Analysis and Evaluation Explained

Neil Jones
|
Senior Consultant at URM
|
|
PUBLISHED on
13
August
2026
Article Summary

In this blog, Neil Jones, Senior Consultant at URM, explains what ISO 27001 Clause 9.1 is really asking for and why monitoring, measurement, analysis and evaluation matter in practice.  The aim is to make the Clause feel less theoretical by showing how it can help organisations understand whether their information security management system (ISMS) is working as intended, where improvements are needed and what evidence should be retained for audit purposes.  Neil outlines:

  • What organisations should monitor
  • How methods and responsibilities should be defined
  • What criteria help determine acceptable performance
  • How results should be analysed, reported and used to drive continual improvement and maintain a robust, audit ready ISMS.

Clause 9.1 of ISO 27001 is all about checking whether your ISMS is working effectively.  It requires organisations to decide what information security measures and performance indicators they need to monitor, how and when they will be measured, who is responsible for carrying out the monitoring, and how the results will be reviewed.

The Clause also requires organisations to keep appropriate records of these activities and use the findings to assess how well the ISMS is performing and whether it is achieving its intended objectives.

What Does Conformance to Clause 9.1 Involve?

Clause 9.1 is about putting a clear and repeatable approach in place.  In practical terms, this means deciding what information will help you judge whether the ISMS is performing well, how that information will be gathered, who will review it and what will happen when the results show that something needs attention.

Define what needs to be monitored and measured  

First, you will need to identify the ISMS elements that require ongoing oversight.  These will become the foundation of your ISMS performance measurement framework.  

We often find that organisations already have much of the information they need, but it is not always brought together in a way that supports ISMS decision-making.

In our experience, many organisations find it difficult to determine what information should be monitored and measured within their ISMS.  In reality, the answer is relatively simple.  Your organisation should focus on monitoring and measuring the aspects of information security that provide meaningful and reliable information about how well your management system is performing.

The aim is to collect data that helps your management at all levels understand whether information security objectives are being achieved, whether the risk assessment and treatments are effective, whether controls are operating effectively, and whether any areas require attention or improvement.  Effective measures should provide practical insight, support informed decision-making, and highlight where corrective action may be needed.

In our experience, the best starting point is to focus on measures that help management understand performance, risk and action, rather than trying to measure everything at once.

Typical areas to be monitored can include, but are not limited to:

  • Control maturity: an assessment of how effectively security controls are implemented or are performing, which can draw directly from internal and external audit results
  • Information security objectives: progress towards the achievement of information security objectives.  These can either be long-standing objectives or those defined on a year-to-year basis.  Regular monitoring of their progress can indicate that they are achievable, or prompt intervention in the event that they appear to be failing
  • Audit and assurance reviews: delivery and results of internal and external audits
  • Risk management: performance of ongoing risk management activities, for example the regular review of open and accepted risks
  • Information security incident management: incident trends and response times
  • Vulnerability management: performance of regular vulnerability scans and treatment of identified vulnerabilities
  • Supplier management: records of performance of suppliers against information security requirements
  • Information security training: records of timely completion of information security training, indicative results of assessments included as part of the training and escalation following non-completion of training
  • Conformance status: completion of planned conformance-related activities on time and as scheduled
  • Management reviews: completion of ISMS management reviews on schedule and outputs from the reviews (note that monitoring and measurement can be an input to the management reviews, and subsequently draw on the outputs from management reviews to provide a feedback loop)
  • Compliance with policies and procedures: records of employee attestations to comply with the information security policy and requirements of the ISMS.

You may also choose to monitor additional areas where doing so provides useful insight and helps inform management decisions.  ISO 27001:2022 introduced Annex A Control 8.16, Monitoring Activities, which requires networks, systems and applications to be monitored for abnormal or suspicious behaviour.  The purpose is to help identify potential information security incidents and ensure appropriate action is taken when issues are detected.  With this in mind, you should consider whether additional monitoring and reporting in key risk areas could provide valuable assurance and support continual improvement.  Some additional themes that may be worth considering include:

  • Substantial upload / download of organisational data to personal drives / devices: this may provide an insight into an employee’s future intentions towards your organisation and indicate issues with data leakage
  • Infrequent activity during WFH: modern working practices make the regular output of staff difficult to assess.  However infrequent activity or regular activity with no tangible output may indicate staff diversions or the use of technical means to simulate system interactions
  • Type, source and frequency of information security incidents: even with the most effective training and awareness practices in place, an occasional lapse may lead to a (hopefully low impact) security incident.  By recording and monitoring trends in this area, repeat offenders may be identified and remedial training provided to those individuals where needed.  

We often find that monitoring programmes become too broad, with organisations collecting data simply because it is available.  While it is important not to collect excessive amounts of data or produce statistics for their own sake, selecting the right metrics can provide valuable insight into the performance of the ISMS.  Meaningful measures help management understand how well information security is performing, identify emerging issues, and focus attention on the areas that matter most.

Establish methods for monitoring and measurement

To ensure consistency and repeatability, you must define methods for the monitoring and measurement of each item (control maturity, training, objectives, etc.) identified in the previous step.  

You will need to establish how the item will be monitored.  Depending on the item in question, this could be through the use of automated tools (for example reports generated from an incident management system), manual review of records (such as risk management reviews), audits (summaries of audit results), or some other mechanism.

From what we see in practice, the challenge is rarely a lack of data.  It is making sure the right data is reviewed by the right people at the right time.

In addition, you must determine how the item will be measured.  This could include the use of key performance indicators (KPIs), such as completion of objectives against target dates, or thresholds to allow response to items that demand attention.  For example, you may set a threshold of ‘no critical information security incidents in the quarter’, whereby the occurrence of any such incident would trigger a wider review of information security and the ISMS to determine how further events can be avoided.  Scoring models, which are structured, numerical frameworks used to evaluate, rank, and prioritise options, may also be applied, although their complexity means they would only be recommended for the most mature ISMS’.

Finally, you need to define what data sources will be used, which could be as simple as audit reports to more complex data structures that allow for information extraction, such as a database of vulnerabilities identified, as well as defining what tools or systems support the process.

Define frequency and responsibilities for monitoring

Your organisation needs to clearly define when monitoring and measurement activities occur, and who is responsible for the activities, ensuring the frequencies and individuals you select are appropriate for the nature of that activity.  You may, for example, decide to conduct daily log reviews (as part of incident management, perhaps), monthly KPI reporting, quarterly vulnerability scans or annual internal audits.  Meanwhile, the ISMS Manager may be responsible for monitoring details of scheduled ISMS activities, while the IT Security Team, CISO, etc., undertake vulnerability management-related monitoring and measurement, HR monitor training metrics and Procurement perform supplier monitoring.

This information can be set out in a roles and responsibilities document, or within process documentation.  Regardless of where these details are documented, you must ensure all significant points are covered unambiguously (i.e., similar responsibilities are not allocated to multiple individuals, creating confusion over who should be doing what).

Document criteria for acceptable performance

To facilitate meaningful, consistent and repeatable performance evaluation, you need to define what ‘good’ ISMS performance looks like, including:

  • Target values: the definition of what would be an acceptable result, for example that the expected completion rate for information security training is 100% of employees
  • Tolerances: an acceptable variation from the ideal, expected result, such as 90% completion of information security training to accommodate cases of long-term absence (e.g., maternity/paternity leave)
  • Thresholds and trigger points for corrective action: this means deciding the point at which a result is no longer acceptable and should trigger action, such as looking into the issue or putting a corrective measure in place.

Collect and record data

Your organisation needs to be able to evidence that the processes it has defined have been implemented.  Your processes need to show how you collect evidence (e.g., information from system logs, management reports, audits, vulnerability scans, or training records).  They should also make sure the data you collect is accurate, complete, stored securely, and, where possible, gathered using automated tools to reduce mistakes.

Analyse and evaluate the results

The collection of information as set out above delivers little value if the results of the monitoring and measurement aren’t analysed and evaluated.  As such, you need to establish how such analysis and evaluation will be undertaken, for example how you will:

  • Identify trends, anomalies, and recurring issues
  • Compare results against targets and thresholds
  • Assess whether controls are effective
  • Determine if risks are increasing or decreasing
  • Evaluate whether information security objectives are being met.

The outcome of the analysis will feed directly into management reviews (Clause 9.3).

Report findings to management

In our experience, simple reporting that clearly links performance, risk and action is usually more valuable than a detailed dashboard that no one uses.

As well as feeding results into management reviews, the most effective monitoring and measurement strategies feed results to executive management throughout the year to give them the insight they need to make operational decisions.  This can be provided through regular ISMS oversight meetings (perhaps a quarterly security oversight committee), or through regular written reports.  It is important to ensure that in all reports to executive management, summaries are clear, evidence-based, linked to risks and/or objectives and identify achievable actions.

Trigger corrective actions where needed

Monitoring and measurement may show that parts of your ISMS are not working as intended, or simply highlight opportunities for improvement.  After all, there is little value in collecting and reviewing information if it does not help you improve.

When monitoring identifies opportunities to enhance the ISMS, these should be managed through your continual improvement process (Clause 10.1).  Where the results reveal a gap in the ISMS or indicate that controls or processes are not operating effectively, a nonconformity and corrective action should be raised in line with Clause 10.2.

Depending on the issue identified, this may lead to updates to risk assessments, improvements to existing controls, the introduction of new controls, changes to processes, or revisions to your information security objectives.

Maintain documented information

As well as documenting your monitoring and measurement processes, including what is monitored, how it is measured and who is responsible, you should retain evidence of the results and any analysis or evaluation carried out.

We often find that the strongest evidence is produced naturally through regular ISMS activity, rather than pulled together at the last minute before an audit.

Keeping these records is important because they demonstrate that your ISMS is being monitored and reviewed effectively.  As a minimum, you should retain at least 12 months of evidence to support external audits and assessments.  However, retaining records for the full three-year certification cycle is generally considered good practice, as it helps you demonstrate trends, continual improvement and ongoing conformance.

Build monitoring and measurement into the ISMS design

The approach for monitoring and measuring needs to be built into the ISMS in the early stages of its development.  As part of a Stage 1 ISO 27001 audit, an external assessor will expect to see these processes in place, whilst by Stage 2 the assessor will expect you to provide evidence of the information being gathered.  Failure to define the approach ahead of a Stage 1 assessment is likely to prevent certification progressing.

Why Does Monitoring, Measurement, Analysis and Evaluation Matter?

For your ISMS to work effectively, it needs to fit the way your organisation operates and support your business objectives.  While leadership support is necessary to achieve this, it is equally necessary to monitor how well an ISMS is performing and feed that information back to the individuals sponsoring information security within the organisation (i.e., top management).  Monitoring ISMS performance is a key tool for management to ensure information security is being managed consistently and appropriately, and in turn maintain ISO 27001 certification.  It is also central to the ISMS’ continual improvement, a concept at the heart of the Standard.  When Clause 9.1 is applied properly, your organisation can show that the ISMS is working, spot and fix issues before they turn into major problems, find ways to improve, and keep your security measures up to date with changing risks and goals.

How URM Can Help

Leveraging 2 decades of experience assisting organisations’ ISO 27001 implementation, URM is the ideal partner to support any aspect of your organisation’s conformance to the Standard.  

Our large team of consultants can offer a range of ISO 27001 consultancy services to help you meet the Standard’s requirements; for example, we can conduct an ISO 27001 gap analysis where we establish your current level of conformance, and help you conduct your risk assessment using our proven risk assessment tool, Abriska 27001.  Following this, we can work with you to develop policies, processes and ISMS infrastructure, always ensuring that these are both aligned with the Standard’s requirements and your organisation’s unique needs.  URM can also offer a range of ISO 27001 internal audit services, including conducting an internal audit ahead of your certification assessment to ensure you are conformant, planning and implementing a full 3-year audit programme, or auditing more specific ISMS areas or particular controls.

As well as consultancy services, URM regularly delivers ISO 27001-related training courses.  Our Introduction to ISO 27001 Course explores all aspects of information security and the importance of ISO 27001 in protecting information, whilst our Certificate in Information Security Management Principles (CISMP) Training Course will fully prepare you to sit and pass the BCS-invigilated examination and gain an industry-recognised information security qualification.

Neil Jones
Neil Jones
Senior Consultant at URM
Neil is a Senior Consultant at URM, with over 20 years of ‘real world’ information security knowledge and experience, having worked in complex telecommunications, (multinational) financial services and professional services environments, with both regional and global responsibilities.

Are you looking to implement ISO 27001? Or certify against the Standard?

URM offers a host of consultancy services to assist you implement and maintain ISO 27001, including gap analyses, risk assessments, policy development, auditing and training.
Thumbnail of the Blog Illustration
Information Security
Published on
13/3/2024
How to Meet the ISO 27001 Requirements Around Interested Parties

URM’s blog provides advice and guidance on how you can meet the ISO 27001 requirements around interested parties and their needs and expectations.

Read more
Thumbnail of the Blog Illustration
Other Standards
Published on
1/3/2024
ISO and IAF add Climate Change Considerations to 31 Management Systems Standards

On 22 February 2024 ISO and IAF released a joint statement relating to an amendment to a total of 31 existing Annex SL management system standards.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
3/7/2025
ISO 27001:2022 - A.5 Organisational Controls (Incident Management)

URM’s blog breaks down the six incident management-related controls in Annex A of ISO 27001, providing key guidance on how to implement each control.

Read more
Great presentation - looking forward to your future events.
Webinar 'ISO 27001 Internal Auditing, the 6 Pillars of Success'
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.