ISO/IEC 27004
ISO/IEC 27004 is a guidance standard that helps organizations measure how well their information security efforts and their information security management system (ISMS) are performing. Rather than setting requirements you must meet, it offers advice on how to develop and use meaningful security metrics. It supports the monitoring, measurement, analysis, and evaluation activities that an ISMS is expected to carry out.
ISO/IEC 27004:2016 provides guidelines to assist organizations in evaluating information security performance and the effectiveness of an ISMS in order to fulfil the monitoring, measurement, analysis, and evaluation requirements associated with ISO/IEC 27001. It addresses (a) the monitoring and measurement of information security performance and (b) the monitoring and measurement of the effectiveness of an ISMS, including its processes and controls. As a guidance document it is advisory rather than certifiable; ISO/IEC 27001 clauses 4 through 10 contain the certifiable ISMS requirements, and 27004 supports the measurement obligations found within those requirements without adding independent conformity criteria. Practitioners should note that a later edition of 27004 has been under development, so the specific content and structure depend on the version referenced.
Why it matters
ISO/IEC 27001 requires an organization to monitor, measure, analyze, and evaluate the performance of its information security management system, but the standard itself provides limited guidance on how to design a measurement program that produces meaningful results. ISO/IEC 27004 fills that gap. It helps organizations move beyond simply asserting that controls exist toward demonstrating, with evidence, how well those controls and the ISMS as a whole are actually performing. This matters because certification and continual improvement both depend on credible data rather than assumptions.
Without a disciplined approach to measurement, security teams risk collecting metrics that are easy to gather but tell them little about actual effectiveness, or reporting numbers that cannot support decisions. By offering guidance on developing and using meaningful information security metrics, ISO/IEC 27004 helps organizations connect their measurement activities to the monitoring, measurement, analysis, and evaluation obligations found within the ISO/IEC 27001 requirements. In most engagements, well-constructed metrics also make it easier to communicate security posture to management and to support the evaluation activities an ISMS is expected to perform.
It is important to keep the standard's role in perspective. ISO/IEC 27004 is guidance, not a certifiable requirement, so an organization does not get certified against it and following it does not by itself demonstrate conformity. The certifiable ISMS requirements remain in ISO/IEC 27001 clauses 4 through 10; ISO/IEC 27004 simply supports the measurement obligations within those requirements without adding independent conformity criteria.
Who it's relevant to
Inside ISO/IEC 27004
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27004.