Skip to main content
Category: Logging and Monitoring

ISO/IEC 27004

Also known as: ISO 27004, ISO/IEC 27004:2016
Simply put

ISO/IEC 27004 is a guidance standard that helps organizations measure how well their information security efforts and their information security management system (ISMS) are performing. Rather than setting requirements you must meet, it offers advice on how to develop and use meaningful security metrics. It supports the monitoring, measurement, analysis, and evaluation activities that an ISMS is expected to carry out.

Formal definition

ISO/IEC 27004:2016 provides guidelines to assist organizations in evaluating information security performance and the effectiveness of an ISMS in order to fulfil the monitoring, measurement, analysis, and evaluation requirements associated with ISO/IEC 27001. It addresses (a) the monitoring and measurement of information security performance and (b) the monitoring and measurement of the effectiveness of an ISMS, including its processes and controls. As a guidance document it is advisory rather than certifiable; ISO/IEC 27001 clauses 4 through 10 contain the certifiable ISMS requirements, and 27004 supports the measurement obligations found within those requirements without adding independent conformity criteria. Practitioners should note that a later edition of 27004 has been under development, so the specific content and structure depend on the version referenced.

Why it matters

ISO/IEC 27001 requires an organization to monitor, measure, analyze, and evaluate the performance of its information security management system, but the standard itself provides limited guidance on how to design a measurement program that produces meaningful results. ISO/IEC 27004 fills that gap. It helps organizations move beyond simply asserting that controls exist toward demonstrating, with evidence, how well those controls and the ISMS as a whole are actually performing. This matters because certification and continual improvement both depend on credible data rather than assumptions.

Without a disciplined approach to measurement, security teams risk collecting metrics that are easy to gather but tell them little about actual effectiveness, or reporting numbers that cannot support decisions. By offering guidance on developing and using meaningful information security metrics, ISO/IEC 27004 helps organizations connect their measurement activities to the monitoring, measurement, analysis, and evaluation obligations found within the ISO/IEC 27001 requirements. In most engagements, well-constructed metrics also make it easier to communicate security posture to management and to support the evaluation activities an ISMS is expected to perform.

It is important to keep the standard's role in perspective. ISO/IEC 27004 is guidance, not a certifiable requirement, so an organization does not get certified against it and following it does not by itself demonstrate conformity. The certifiable ISMS requirements remain in ISO/IEC 27001 clauses 4 through 10; ISO/IEC 27004 simply supports the measurement obligations within those requirements without adding independent conformity criteria.

Who it's relevant to

ISMS Managers and ISO 27001 Program Owners
Those responsible for operating an ISMS use ISO/IEC 27004 to help design a measurement program that satisfies the monitoring, measurement, analysis, and evaluation obligations within ISO/IEC 27001. It supports demonstrating, with evidence, that controls and the ISMS are performing as intended.
Security Metrics and Reporting Teams
Teams tasked with developing and reporting information security metrics can draw on the standard's guidance to move from easily gathered but low-value numbers toward metrics that meaningfully reflect performance and effectiveness, and that support management decisions.
Internal Auditors and Certification Preparation Staff
Because ISO/IEC 27001 requires evaluation activities but says little about how to measure, internal auditors and those preparing for certification can use ISO/IEC 27004 as guidance for assessing whether measurement practices adequately support the ISMS requirements. Note that the standard itself is not certifiable.
GRC and Compliance Leaders
Governance, risk, and compliance professionals overseeing multiple frameworks benefit from a structured basis for security measurement, while recognizing that ISO/IEC 27004 is advisory and does not add independent conformity criteria beyond the ISO/IEC 27001 requirements it supports.

Inside ISO/IEC 27004

Purpose and Scope
ISO/IEC 27004 is a guidance standard that supports the monitoring, measurement, analysis, and evaluation requirements of ISO/IEC 27001 (notably clause 9.1). It provides guidance on how to assess the performance and effectiveness of an information security management system (ISMS), rather than adding certifiable requirements of its own.
Non-Certifiable Nature
Unlike ISO/IEC 27001, this standard is not a standard against which an organization is certified. It offers supporting guidance and does not, by itself, form the basis of an accredited certification.
Measurement Concepts
The standard describes concepts used to build a measurement program, typically distinguishing between base measures, derived measures, and indicators, and explaining how raw data can be processed into information useful for decision-making. Exact terminology and structure depend on the edition consulted.
Relationship to ISMS Performance Evaluation
It helps an organization determine what to monitor and measure, the methods for monitoring and measurement, and when results should be analyzed and evaluated, aligning with the performance evaluation expectations set out in ISO/IEC 27001.
Illustrative Examples
The document generally includes example measurement constructs to demonstrate how metrics might be defined and applied. These are intended as illustrations to be adapted to context, not as mandatory or universally applicable measures.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27004.

Is ISO/IEC 27004 a certifiable standard that auditors check during an ISO 27001 audit?
No. ISO/IEC 27004 is a guidance standard offering recommendations on monitoring, measurement, analysis, and evaluation of information security performance and the ISMS. It is not itself certifiable. The certifiable requirements sit in clauses 4 through 10 of ISO/IEC 27001. ISO/IEC 27001 does require an organization to evaluate information security performance and ISMS effectiveness, and ISO/IEC 27004 provides guidance to help satisfy that requirement, but a certification body certifies against ISO/IEC 27001, not against ISO/IEC 27004. Following ISO/IEC 27004 is typically optional and supportive rather than mandatory.
Does ISO/IEC 27004 give me a fixed set of security metrics I must report on?
No. ISO/IEC 27004 does not prescribe a mandatory list of metrics that every organization must use. It provides guidance and illustrative approaches for developing measures suited to your own context, objectives, and risk profile. The specific metrics an organization chooses typically depend on its ISMS scope, security objectives, and stakeholder needs. Treat the examples in the standard as illustrative rather than as a required checklist.
How does ISO/IEC 27004 relate to the performance evaluation requirements in ISO/IEC 27001?
ISO/IEC 27001 requires the organization to determine what needs to be monitored and measured, the methods used, and when results are analyzed and evaluated, as part of performance evaluation. ISO/IEC 27004 offers guidance on how to design and operate that measurement activity, helping an organization decide what to measure and how to interpret results. In most implementations it is used as a companion reference to support the clause requirements rather than as a separate obligation.
How do I decide which security measures to develop using ISO/IEC 27004 guidance?
The guidance generally encourages linking measures to your defined information security objectives and the needs of relevant stakeholders, so that results support decision-making and improvement of the ISMS. In practice, organizations typically select measures based on their scope, risk assessment outcomes, and control priorities, then define how data is collected, analyzed, and reported. Selection depends on context, and what is meaningful varies from one organization to another.
Can ISO/IEC 27004 help demonstrate ISMS effectiveness to an auditor or certification body?
It can support that objective. Applying its guidance can help an organization produce documented monitoring and measurement results that evidence how it evaluates ISMS performance and effectiveness, which is relevant to the performance evaluation requirements of ISO/IEC 27001. However, certification decisions rest on conformance to ISO/IEC 27001 as assessed by the certification body, and the value of any measurement approach depends on how well it fits the defined scope.
Does ISO/IEC 27004 overlap with SOC 2 monitoring expectations?
There can be conceptual overlap, since both frameworks value monitoring and evaluation of controls, but they are distinct. ISO/IEC 27004 provides measurement guidance within the ISO 27001 ISMS context, while a SOC 2 examination assesses controls against the applicable Trust Services Criteria under the AICPA SSAE 18 standard and results in a report rather than a certification. Metrics developed under ISO/IEC 27004 guidance may inform monitoring activities relevant to both, but applying one framework's guidance does not automatically satisfy the other; mapping between them is typically partial and depends on scope.

Common misconceptions

An organization can be certified against ISO/IEC 27004.
ISO/IEC 27004 is guidance and is not certifiable. Accredited certification is issued against ISO/IEC 27001, whose clauses 4 through 10 contain the certifiable ISMS requirements; ISO/IEC 27004 supports the measurement activities that inform 27001 conformity.
ISO/IEC 27004 prescribes a fixed, mandatory set of security metrics that every organization must use.
The standard provides guidance and illustrative examples rather than a required list of metrics. In most implementations, the measures an organization selects depend on its objectives, risk assessment, and ISMS scope, and should be tailored accordingly.
ISO/IEC 27004 measurement satisfies SOC 2 monitoring expectations automatically.
ISO/IEC 27004 relates to the ISO 27001 ISMS and does not automatically satisfy SOC 2 requirements. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and is evaluated against the Trust Services Criteria; mapping between the frameworks is at most partial, and satisfying one does not automatically satisfy the other.

Best practices

Align your measurement program with ISO/IEC 27001 clause 9.1 by explicitly defining what will be monitored and measured, the methods used, and when analysis and evaluation will occur.
Treat the standard's example metrics as adaptable illustrations, selecting measures that reflect your organization's information security objectives, risk assessment, and defined ISMS scope rather than adopting them wholesale.
Distinguish base measures, derived measures, and indicators when designing metrics so that raw data is consistently translated into information that supports management decisions.
Assign clear ownership and defined reporting cadence for each measure so that results feed into management review and continual improvement of the ISMS.
Verify the edition of ISO/IEC 27004 you are relying on, since terminology and illustrative content can vary between versions, and cite guidance qualitatively where specifics differ.
Keep measurement outputs documented as evidence to support the performance evaluation activities an ISO 27001 certification body may review within the defined scope of your ISMS.