27004-10.1 | Programme Review and Improvement | 0 |
27004-4 | Structure and overview | 0 |
27004-5.1 | Need for Measurement | 0 |
27004-5.2 | Fulfilling 27001 Requirements | 0 |
27004-5.3 | Validity of Results | 0 |
27004-6.1 | What to Monitor and Measure | 0 |
27004-6.2 | Who to Monitor and Measure | 0 |
27004-6.3 | When to Monitor and Measure | 0 |
27004-6.4 | How to Monitor and Measure | 0 |
27004-7.1 | Performance Indicators | 1 |
27004-7.2 | Effectiveness Indicators | 0 |
27004-7.3 | Measurement Construct | 0 |
27004-8.1 | Data Collection | 0 |
27004-8.2 | Analysis | 3 |
27004-8.3 | Evaluation of measures | 0 |
27004-8.4 | Review and improvement of processes | 0 |
27004-9.1 | Evaluation of Results | 0 |
27004-9.2 | Communication and Reporting | 13 |
27004-A.1 | Coverage Measures | 0 |
27004-A.2 | Patching and Vulnerability Measures | 169 |
27004-A.3 | Incident Measures | 0 |
27004-A.4 | Awareness and Training Measures | 1 |
27004-A.5 | Access Control Measures | 1 |
27004-A.6 | Third-Party Measures | 0 |
27004-B.1 | Example measurement definitions | 169 |
27004-B.2 | Control effectiveness examples | 0 |
27004-B.3 | Process performance examples | 0 |
1-3 | Scope, normative references, terms and definitions | 0 |
4 | Structure and overview | 0 |
5.1 | The need for measurement | 0 |
5.2 | Fulfilling the ISO/IEC 27001 requirements | 0 |
5.3 | Validity of results | 0 |
5.4 | Benefits | 0 |
6.1 | General: measure to the information need | 0 |
6.2 | What to monitor | 0 |
6.3 | What to measure | 0 |
6.4 | When to monitor, measure, analyse and evaluate | 0 |
6.5 | Who will monitor, measure, analyse and evaluate | 0 |
7.1 | General: performance measures and effectiveness measures | 0 |
7.2 | Performance measures | 0 |
7.3 | Effectiveness measures | 0 |
8.1 | The monitoring, measurement, analysis and evaluation processes | 0 |
8.2 | Identify information needs | 0 |
8.3 | Create and maintain measures | 0 |
8.3.1 | Create measures once, then review and update them at planned intervals and on substantial change | 0 |
8.3.2 | Identify current security practices that can support information needs | 0 |
8.3.3 | Develop or update measures | 0 |
8.3.4 | Document measures and prioritise for implementation | 0 |
8.3.5 | Keep management informed and engaged | 0 |
8.4 | Establish procedures | 0 |
8.5 | Monitor and measure | 0 |
8.6 | Analyse results | 0 |
8.7 | Evaluate information security performance and ISMS effectiveness | 0 |
8.8 | Review and improve the monitoring, measurement, analysis and evaluation processes | 0 |
8.9 | Retain and communicate documented information | 0 |
A | Annex A: the information security measurement model | 0 |
B | Annex B: measurement construct examples (B.1 mapping table) | 0 |
B.10 | Corrective action implementation | 0 |
B.11 | ISMS training or ISMS awareness | 0 |
B.12 | Information security training | 0 |
B.13 | Information security awareness compliance | 0 |
B.14 | ISMS awareness campaigns effectiveness | 0 |
B.15 | Social engineering preparedness | 0 |
B.16 | Password quality, manual | 0 |
B.17 | Password quality, automated | 0 |
B.18 | Review of user access rights | 0 |
B.19 | Physical entry controls system evaluation | 0 |
B.2 | Resource allocation | 0 |
B.20 | Physical entry controls effectiveness | 0 |
B.21 | Management of periodic maintenance | 0 |
B.22 | Change management | 0 |
B.23 | Protection against malicious code | 0 |
B.24 | Anti-malware | 0 |
B.25 | Total availability | 0 |
B.26 | Firewall rules | 0 |
B.27 | Log files review | 0 |
B.28 | Device configuration | 0 |
B.29 | Pentest and vulnerability assessment | 0 |
B.3 | Policy review | 0 |
B.30 | Vulnerability landscape | 0 |
B.31 | Security in third party agreements, A | 0 |
B.32 | Security in third party agreements, B | 0 |
B.33 | Information security incident management effectiveness | 0 |
B.34 | Security incidents trend | 0 |
B.35 | Security event reporting | 0 |
B.36 | ISMS review process | 0 |
B.37 | Vulnerability coverage | 0 |
B.4 | Management commitment | 0 |
B.5 | Risk exposure | 0 |
B.6 | Audit programme | 0 |
B.7 | Improvement actions | 0 |
B.8 | Security incident cost | 0 |
B.9 | Learning from information security incidents | 0 |
C | Annex C: a free-form measurement construct (training effectiveness) | 0 |