Skip to main content
Category: Logging and Monitoring

Monitoring, Measurement, Analysis and Evaluation

Also known as: MMAE, ISO 27001 Clause 9.1, Clause 9.1, Monitoring, Measurement, Analysis and Performance Evaluation
Simply put

Monitoring, Measurement, Analysis and Evaluation is the part of ISO 27001 (Clause 9.1) that requires an organization to keep track of how well its information security management system is actually working. It involves deciding what to measure, collecting the data, analyzing it, and evaluating the results so leaders can understand the security posture and make informed decisions. Think of it as the dashboard that shows whether the security controls and processes are performing as intended.

Formal definition

Under ISO/IEC 27001, Clause 9.1 (Monitoring, Measurement, Analysis and Evaluation) is an ISMS requirement within clauses 4 through 10 that obligates an organization to determine what needs to be monitored and measured, the methods used, when monitoring and measurement are performed, and when results are analyzed and evaluated. The intent is to assess the performance and effectiveness of the information security management system and its controls, with documented information typically retained as evidence of the results. The specific metrics, methods, and cadence are determined by the organization based on its context and scope rather than prescribed by the standard, so implementation varies across engagements. Note that Clause 9.1 addresses the effectiveness of the ISMS overall and should be distinguished from the reference controls in Annex A, which are selected via the Statement of Applicability; a comparable monitoring concept also appears in other management system standards such as ISO 9001.

Why it matters

Clause 9.1 is what turns an ISO 27001 information security management system from a static set of documented policies into something an organization can actually steer. Without deciding what to monitor and measure, how to collect the data, and how to analyze and evaluate the results, leadership has no reliable way to know whether the ISMS and its controls are performing as intended. The clause provides the evidence base that management review and continual improvement depend on, functioning as the dashboard that reveals whether security processes are working or drifting.

For certification, this matters because Clause 9.1 sits among the ISMS requirements in clauses 4 through 10, the certifiable portion of the standard against which an accredited certification body assesses conformity. Auditors typically look for evidence that the organization has determined what needs to be measured, the methods used, the timing of monitoring and measurement, and when results are analyzed and evaluated, along with documented information retained as evidence of those results. Weakness here can surface as a nonconformity even where individual controls appear to be in place, because the organization cannot demonstrate that it evaluates their effectiveness.

It is worth emphasizing what Clause 9.1 does not do. It addresses the effectiveness of the ISMS overall and should be distinguished from the reference controls in Annex A, which are selected through the Statement of Applicability. The standard does not prescribe specific metrics, methods, or cadence; those are determined by the organization based on its context and scope, so implementation varies from one engagement to the next.

Who it's relevant to

ISMS and Compliance Managers
These roles own the decisions about what to monitor and measure, the methods used, and the cadence for analysis and evaluation. They are responsible for ensuring documented information is retained as evidence and that results feed into management review and decision-making about the security posture.
Internal and Certification Auditors
Auditors examine whether the organization has determined what needs to be measured, how, and when, and whether results are analyzed and evaluated. Because Clause 9.1 falls within the certifiable ISMS requirements, gaps here can be raised as findings even when individual controls appear operational.
Security Engineers and Operations Teams
These teams often generate and collect the underlying data that feeds monitoring and measurement, translating operational telemetry into inputs that can be analyzed and evaluated against the organization's chosen metrics.
Executive Leadership
Leaders rely on the analyzed and evaluated results as a dashboard of ISMS performance and effectiveness, using them to understand the organization's security posture and make informed decisions about resourcing and improvement.
Integrated Management System Teams
Organizations running an integrated management system may coordinate Clause 9.1 activities across standards, since a comparable monitoring, measurement, analysis and evaluation concept also appears in ISO 9001, allowing shared processes where appropriate.

Inside MMAE

ISO 27001 Clause 9.1
The ISMS requirement addressing monitoring, measurement, analysis, and evaluation. It obligates the organization to determine what needs to be monitored and measured, the methods used, when monitoring is performed, and who evaluates the results, so that the effectiveness of the ISMS and its controls can be assessed.
Determining what to monitor and measure
The organization identifies the information security processes and controls whose performance and effectiveness need to be tracked. The specific selections depend on the defined scope of the ISMS and the results of the risk assessment rather than a fixed universal list.
Methods for monitoring, measurement, analysis, and evaluation
The chosen methods should, where practicable, produce comparable and reproducible results so that outcomes can be evaluated consistently over time. The appropriate methods vary depending on scope and the nature of the processes being measured.
Timing and responsibility
Requirements to define when monitoring and measurement are performed and when results are analyzed and evaluated, along with assigning responsibility for who performs monitoring and who evaluates the results.
Documented evidence of results
The organization is expected to retain appropriate documented information as evidence of the monitoring and measurement results, which supports internal review and can be examined by a certification body during audit.
Relationship to the broader ISMS
Outputs from monitoring and measurement feed into other ISMS requirements in clauses 4 through 10, such as internal audit, management review, and continual improvement, forming part of the ongoing evaluation of ISMS performance.

Common questions

Answers to the questions practitioners most commonly ask about MMAE.

Is Clause 9.1 the same thing as an internal audit under ISO 27001?
No. Clause 9.1 (Monitoring, Measurement, Analysis and Evaluation) and the internal audit requirement (Clause 9.2) are distinct activities within the ISMS performance evaluation area. Clause 9.1 focuses on determining what needs to be monitored and measured, the methods used, and when results are analyzed and evaluated to assess ISMS performance and effectiveness. The internal audit is a separate systematic check of whether the ISMS conforms to requirements and is effectively implemented. Both fall under clauses 4 through 10, but treating them as interchangeable misrepresents the standard's structure.
Does Clause 9.1 require a specific set of metrics or key performance indicators?
No. The standard does not prescribe a fixed list of metrics or mandated KPIs. It requires the organization to determine what needs monitoring and measurement, along with the methods, timing, and responsibilities for analysis and evaluation. The selection typically depends on the organization's objectives, risk assessment, and scope, so what is measured varies from one ISMS to another. Avoid assuming any particular indicator is universally required.
How do we decide what to monitor and measure to satisfy Clause 9.1?
In most implementations, organizations align monitoring and measurement with their information security objectives, the results of their risk assessment, and the controls selected through the Statement of Applicability. The intent is to produce data that meaningfully reflects ISMS performance and control effectiveness. The specific choices depend on scope and context and should be defined so results are comparable and reproducible over time.
How often should monitoring, measurement, analysis, and evaluation be performed?
The standard requires the organization to determine when monitoring and measurement are performed and when the resulting data is analyzed and evaluated, but it does not fix a single frequency. Timing typically varies by the nature of what is being measured and by scoping decisions, with some measures assessed continuously and others periodically. The chosen intervals should be defined and consistent enough to support meaningful evaluation.
What evidence do we need to retain to demonstrate conformity with Clause 9.1?
Organizations are generally expected to retain documented information as evidence of the monitoring and measurement results. In practice this may include records showing what was measured, the methods applied, when it was performed, and the analysis and evaluation of the outcomes. The precise form of the records depends on the organization's documented processes, and a certification body will assess these against the defined scope of the ISMS.
How does Clause 9.1 feed into other parts of the ISMS?
The results of monitoring, measurement, analysis, and evaluation typically serve as inputs to management review (Clause 9.3) and can inform decisions about improvement and corrective action (Clause 10). This creates a feedback loop where performance data supports evaluation of whether objectives are being met and whether the ISMS remains effective. The exact linkages depend on how the organization structures its processes within clauses 4 through 10.

Common misconceptions

Monitoring and measurement under Clause 9.1 requires a fixed, prescribed set of metrics that every organization must adopt.
The standard requires the organization to determine what needs to be monitored and measured, but the specific selections depend on the ISMS scope and risk assessment. There is no universal mandated list, so choices typically vary from one organization to another.
Satisfying ISO 27001 monitoring and measurement requirements automatically demonstrates equivalent monitoring for a SOC 2 examination.
SOC 2 is an attestation examination performed by a CPA firm against the Trust Services Criteria, while ISO 27001 is a certification against a management system standard. Mapping between the two is possible but partial, and satisfying monitoring expectations under one framework does not automatically satisfy the other.
Monitoring and measurement is the same as the ISO 27001 internal audit or management review.
Monitoring and measurement under Clause 9.1 is a distinct activity focused on evaluating the performance and effectiveness of the ISMS and its controls. Its results feed into internal audit and management review, but those are separate requirements within clauses 4 through 10.

Best practices

Define, before measuring, exactly what needs to be monitored and measured based on your ISMS scope and the outputs of your risk assessment, rather than adopting metrics arbitrarily.
Document the methods, timing, and responsibilities for monitoring, measurement, analysis, and evaluation so results can be produced and interpreted consistently.
Select methods that, where practicable, yield comparable and reproducible results so trends and effectiveness can be evaluated over time.
Retain documented information as evidence of monitoring and measurement results, since this supports internal review and can be examined by a certification body during audit.
Feed monitoring and measurement outputs into internal audit, management review, and continual improvement so evaluation drives action rather than sitting in isolation.
Remember that these results attest only to what is monitored within the defined ISMS scope, and periodically reassess whether the selected measures still reflect current risks and scope.