International

ISO/IEC 27004:2016

94 controls. 181 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

94 controls 181 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27004-10.1Programme Review and Improvement0
27004-4Structure and overview0
27004-5.1Need for Measurement0
27004-5.2Fulfilling 27001 Requirements0
27004-5.3Validity of Results0
27004-6.1What to Monitor and Measure0
27004-6.2Who to Monitor and Measure0
27004-6.3When to Monitor and Measure0
27004-6.4How to Monitor and Measure0
27004-7.1Performance Indicators1
27004-7.2Effectiveness Indicators0
27004-7.3Measurement Construct0
27004-8.1Data Collection0
27004-8.2Analysis3
27004-8.3Evaluation of measures0
27004-8.4Review and improvement of processes0
27004-9.1Evaluation of Results0
27004-9.2Communication and Reporting13
27004-A.1Coverage Measures0
27004-A.2Patching and Vulnerability Measures169
27004-A.3Incident Measures0
27004-A.4Awareness and Training Measures1
27004-A.5Access Control Measures1
27004-A.6Third-Party Measures0
27004-B.1Example measurement definitions169
27004-B.2Control effectiveness examples0
27004-B.3Process performance examples0
1-3Scope, normative references, terms and definitions0
4Structure and overview0
5.1The need for measurement0
5.2Fulfilling the ISO/IEC 27001 requirements0
5.3Validity of results0
5.4Benefits0
6.1General: measure to the information need0
6.2What to monitor0
6.3What to measure0
6.4When to monitor, measure, analyse and evaluate0
6.5Who will monitor, measure, analyse and evaluate0
7.1General: performance measures and effectiveness measures0
7.2Performance measures0
7.3Effectiveness measures0
8.1The monitoring, measurement, analysis and evaluation processes0
8.2Identify information needs0
8.3Create and maintain measures0
8.3.1Create measures once, then review and update them at planned intervals and on substantial change0
8.3.2Identify current security practices that can support information needs0
8.3.3Develop or update measures0
8.3.4Document measures and prioritise for implementation0
8.3.5Keep management informed and engaged0
8.4Establish procedures0
8.5Monitor and measure0
8.6Analyse results0
8.7Evaluate information security performance and ISMS effectiveness0
8.8Review and improve the monitoring, measurement, analysis and evaluation processes0
8.9Retain and communicate documented information0
AAnnex A: the information security measurement model0
BAnnex B: measurement construct examples (B.1 mapping table)0
B.10Corrective action implementation0
B.11ISMS training or ISMS awareness0
B.12Information security training0
B.13Information security awareness compliance0
B.14ISMS awareness campaigns effectiveness0
B.15Social engineering preparedness0
B.16Password quality, manual0
B.17Password quality, automated0
B.18Review of user access rights0
B.19Physical entry controls system evaluation0
B.2Resource allocation0
B.20Physical entry controls effectiveness0
B.21Management of periodic maintenance0
B.22Change management0
B.23Protection against malicious code0
B.24Anti-malware0
B.25Total availability0
B.26Firewall rules0
B.27Log files review0
B.28Device configuration0
B.29Pentest and vulnerability assessment0
B.3Policy review0
B.30Vulnerability landscape0
B.31Security in third party agreements, A0
B.32Security in third party agreements, B0
B.33Information security incident management effectiveness0
B.34Security incidents trend0
B.35Security event reporting0
B.36ISMS review process0
B.37Vulnerability coverage0
B.4Management commitment0
B.5Risk exposure0
B.6Audit programme0
B.7Improvement actions0
B.8Security incident cost0
B.9Learning from information security incidents0
CAnnex C: a free-form measurement construct (training effectiveness)0

Tell me when ISO/IEC 27004:2016 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Governance framework doc
  • Board charter
  • RACI matrix
  • access control matrix
  • RBAC documentation
  • access review reports
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27004:2016, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition