6.6 Clause 9: Performance Evaluation
Key Takeaways
- Clause 9 is the 'Check' phase of PDCA, evaluating ISMS performance through monitoring (9.1), internal audit (9.2), and management review (9.3)
- Internal auditors must be independent of the area being audited; the certification audit by an external certification body is separate from the internal audit required by 9.2
- Management review (9.3) is top management's responsibility and cannot be delegated to the CISO or ISMS coordinator alone
- Clause 9.1 requires decisions on what, methods, when, and who — it does not prescribe specific ISMS metrics; metrics tie to the organization's own objectives and risks
- ISO 19011 provides guidance on auditor competence, independence, and audit programme management
Clause 9 is the "Check" phase of PDCA. It answers the question: how do we know the ISMS is working? It has three subclauses — monitoring/measurement, internal audit, and management review — and the Foundation exam tests the distinct purpose of each, plus the critical requirement that internal auditors must be independent.
9.1 Monitoring, Measurement, Analysis and Evaluation
The organization must determine:
- What needs to be monitored and measured
- The methods for monitoring, measurement, analysis, and evaluation, to ensure valid results
- When the monitoring and measurement shall be performed
- When the results shall be analyzed and evaluated
- Who shall perform the monitoring, measurement, analysis, and evaluation
The organization must retain documented information as evidence of the monitoring and measurement results. Note the symmetry with Clause 7.4 (what/when/with whom/how) and Clause 6.2 (objectives must be measurable whenever practicable).
ISMS Metrics Examples
| Metric Category | Example Metrics |
|---|---|
| Incident management | Number of incidents, mean time to detect, mean time to respond |
| Vulnerability management | Open vulnerabilities by severity, patch SLA compliance percentage |
| Training & awareness | Percentage of employees completing mandatory training, phishing simulation click rate |
| Access control | Number of dormant accounts, percentage of privileged accounts reviewed on schedule |
| Business continuity | RTO/RPO achievement in last test, percentage of critical processes tested |
| Supplier security | Number of suppliers with valid ISO/IEC 27001 certification, overdue supplier assessments |
A common trap: Clause 9.1 does NOT prescribe specific metrics — the organization selects them based on its objectives (Clause 6.2) and risks (Clause 6.1). Generic metrics copied from another organization's ISMS are not necessarily effective.
9.2 Internal Audit
Internal audits must be conducted at planned intervals to provide information on whether the ISMS:
- Conforms to the organization's own requirements, the ISO/IEC 27001 requirements, and its information security objectives
- Is effectively implemented and maintained
Audit Programme
The organization must plan, establish, implement, and maintain an audit programme(s) including the frequency, methods, responsibilities, planning requirements, and reporting. The programme considers:
- The importance of the processes concerned
- The results of previous audits
- The organization's information security risks and changes affecting the organization
Auditor Independence
The organization must:
- Select auditors and conduct audits to ensure objectivity and impartiality of the audit process
- Ensure that the results of the audits are reported to relevant management
- Retain documented information as evidence of the audit programme and results
This is the most heavily tested point in Clause 9: internal auditors must be independent of the area being audited. An employee who designs, owns, or operates a process cannot objectively audit that same process. Independence can be achieved by rotating auditors, using auditors from another department, or using external auditors. ISO 19011 (Guidelines for auditing management systems) provides guidance on auditor competence, independence, and audit programme management.
Trap: Internal Audit vs External (Certification) Audit
The certification audit (Stage 1 documentation review and Stage 2 conformity audit) is conducted by an external certification body — it is NOT the internal audit required by Clause 9.2. The Foundation exam may include an answer that confuses certification audit results with internal audit results. Internal audit is the organization's own self-assessment; certification is independent third-party conformity assessment.
9.3 Management Review
Top management must review the organization's ISMS at planned intervals (at least annually in practice, though the standard does not specify a minimum frequency) to ensure its continuing suitability, adequacy, and effectiveness.
Management Review Inputs
The review must include consideration of:
- The status of actions from previous management reviews
- Changes in external and internal issues relevant to the ISMS (Clause 4.1 context)
- Information on the ISMS performance, including trends in:
- Nonconformities and corrective actions
- Monitoring and measurement results (Clause 9.1)
- Audit results (Clause 9.2)
- Fulfilment of information security objectives (Clause 6.2)
- Feedback on the information security performance from interested parties (Clause 4.2)
- Results of risk assessment and status of risk treatment (Clauses 6.1, 8.2, 8.3)
- Opportunities for continual improvement
Management Review Outputs
The outputs of the management review must include decisions related to:
- Continual improvement opportunities
- Any need for changes to the ISMS
- Resource needs
The organization must retain documented information of the management review results as evidence.
Trap: Management Review is Top Management's Responsibility
Management review cannot be delegated to the ISMS coordinator or CISO alone. Top management must be present and engaged — this connects directly to Clause 5.1 leadership commitment. An exam scenario where the CISO alone signs off on the management review is nonconformant.
Common Traps
- Internal auditors must be independent of the audited area. Independence is mandatory, not a best practice.
- Internal audit ≠ certification audit. The certification audit is conducted by an external body; Clause 9.2 requires the organization's own internal audit.
- 9.1 does not prescribe metrics. Metric selection is the organization's responsibility, tied to objectives and risks.
- Management review requires top management. Delegation to the CISO or ISMS coordinator alone is nonconformant.
A small company assigns its network administrator to conduct the ISMS internal audit of the network operations area. Why is this nonconformant with Clause 9.2?
Which of the following is NOT a required output of the management review under Clause 9.3?
Which statement best describes Clause 9.1's requirement regarding ISMS metrics?