Skip to main content
Category: ISMS Clauses and Planning

Performance Evaluation

Also known as: ISO 27001 Clause 9, ISMS Performance Evaluation
Simply put

In the context of ISO/IEC 27001, Performance Evaluation refers to Clause 9 of the standard, which requires an organization to check whether its information security management system (ISMS) is actually working as intended. This is done by monitoring and measuring security activities, running internal audits, and holding management reviews. It is a distinct concept from an employee performance review and instead focuses on how well the security management system itself is performing.

Formal definition

Performance Evaluation is Clause 9 within the certifiable ISMS requirements of ISO/IEC 27001 (clauses 4 through 10). It typically encompasses three sub-areas: monitoring, measurement, analysis and evaluation of the ISMS and its controls; internal audit of the ISMS at planned intervals; and management review, in which top management assesses the ISMS's continuing suitability, adequacy, and effectiveness. The scope, frequency, and methods of these activities are determined by the organization based on its own risk assessment and ISMS scope rather than by fixed prescriptive values, and the outputs commonly feed into Clause 10 (Improvement). Note that this ISO 27001 usage should not be confused with the human-resources sense of 'performance evaluation' as an employee job-performance review; the evidence packet supplied describes only the HR meaning, which is out of scope for this ISMS glossary entry.

Why it matters

Performance Evaluation matters because certification against ISO/IEC 27001 depends on an organization demonstrating not just that an ISMS exists on paper, but that it is being actively checked and shown to be working. Clause 9 is where evidence of this checking is generated: monitoring and measurement data, internal audit results, and records of management review. Without these activities, an organization cannot credibly show that its controls are operating as intended or that top management is engaged in overseeing information security, which are conditions that certification bodies typically look for during audits.

The clause also serves as the feedback loop that keeps an ISMS relevant over time. Threats, business context, and control effectiveness change, and Performance Evaluation is the mechanism through which an organization detects gaps, ineffective controls, or shifting risk before they become larger problems. The outputs of Clause 9 commonly feed directly into Clause 10 (Improvement), so weaknesses in performance evaluation tend to undermine an organization's ability to correct issues and continually improve.

It is important to distinguish this ISO 27001 usage from the human-resources concept of an employee performance review, which shares the same name but is unrelated. In the ISMS context, Performance Evaluation assesses how well the security management system itself is performing, not how individual employees are doing their jobs. Conflating the two leads to misapplied controls and audit findings, so precision in terminology is essential for compliance teams.

Who it's relevant to

ISMS Managers and Coordinators
Those responsible for maintaining an ISO/IEC 27001 ISMS rely on Clause 9 to structure the monitoring, measurement, internal audit, and management review activities that demonstrate the system is functioning. They typically define what is measured and how often, based on the organization's risk assessment and scope.
Internal Auditors
Internal audit is one of the three sub-areas of Clause 9. Auditors plan and conduct audits of the ISMS at planned intervals to verify that it conforms to the standard and the organization's own requirements and is effectively implemented and maintained.
Top Management
Clause 9 requires top management to conduct management reviews assessing the ISMS's continuing suitability, adequacy, and effectiveness. This makes leadership engagement a direct requirement rather than a delegated task, and the review outputs often inform improvement activities.
GRC and Compliance Professionals
Those preparing for or maintaining ISO/IEC 27001 certification use Clause 9 outputs as evidence of an operating ISMS. They also need to keep this ISMS meaning distinct from the unrelated human-resources concept of an employee performance review to avoid misapplied controls or audit findings.

Inside Performance Evaluation

Monitoring, measurement, analysis and evaluation
The requirement to determine what needs to be monitored and measured within the ISMS, the methods used, and when results are evaluated to assess information security performance and the effectiveness of the ISMS. Depending on scope, organizations select metrics that provide meaningful, comparable, and reproducible results.
Internal audit
The requirement to conduct internal audits at planned intervals to determine whether the ISMS conforms to the organization's own requirements and to the ISO/IEC 27001 requirements, and whether it is effectively implemented and maintained. Typically an audit programme is planned, criteria and scope are defined for each audit, and results are reported to relevant management.
Management review
The requirement for top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Inputs typically include audit results, monitoring and measurement outcomes, status of prior actions, changes affecting the ISMS, and improvement opportunities; outputs generally include decisions on improvements and changes.
Documented information as evidence
Clause 9 generally calls for retaining documented information as evidence of the monitoring and measurement results, the audit programme and audit results, and the results of management reviews, which auditors and certification bodies typically examine.

Common questions

Answers to the questions practitioners most commonly ask about Performance Evaluation.

Does Performance Evaluation in ISO/IEC 27001 refer to reviewing employee job performance?
No. In ISO/IEC 27001, Performance Evaluation is Clause 9 of the ISMS requirements and concerns evaluating the information security management system itself, not appraising individual employees' job performance. It addresses monitoring, measurement, analysis and evaluation of the ISMS, internal audit, and management review. Individual staff appraisals are an HR activity and fall outside the intent of this clause, although competence and awareness of personnel are addressed elsewhere in the standard.
Is Performance Evaluation just another name for the internal audit of the ISMS?
Not exactly. Internal audit is one component of Clause 9, but it is not the whole clause. Performance Evaluation typically encompasses three areas: monitoring, measurement, analysis and evaluation of the ISMS; the internal audit programme; and management review. Treating it as only the internal audit would omit the other required activities. The specific structure and sub-clause references depend on the edition of the standard, so the applicable version should be confirmed.
How do we decide what to monitor and measure for our ISMS under Clause 9?
The standard generally expects an organization to determine what needs monitoring and measurement, the methods used, and when results are analysed and evaluated, so that the outcomes are valid. In most implementations these decisions are driven by the organization's information security objectives, its risk assessment, and the controls selected in the Statement of Applicability. What is appropriate varies by scope, and the certification body assesses whether the chosen approach produces meaningful, comparable results rather than mandating specific metrics.
How often should we run internal audits and management reviews?
The standard requires that internal audits and management reviews be conducted at planned intervals, but it does not prescribe a fixed frequency. In most engagements organizations align these with an annual cycle to support the certification programme, though intervals can vary depending on scope, organizational change, and risk. The internal audit programme should also consider the importance of the processes concerned and the results of previous audits. Confirm expectations with your certification body.
What evidence should we retain to demonstrate Performance Evaluation to an auditor?
Typically, organizations retain documented information showing that monitoring and measurement occurred and how results were analysed, records of the internal audit programme and its findings, and minutes or outputs of management reviews including decisions and actions. The precise records expected depend on scope and the certification body's expectations. Retaining evidence over time is particularly relevant because certification covers only the defined scope of the ISMS and auditors examine the activities actually performed.
What inputs and outputs are expected from a management review under Clause 9?
Management review generally considers inputs such as the status of actions from prior reviews, changes affecting the ISMS, feedback on security performance including monitoring and audit results, and opportunities for improvement. Outputs typically include decisions related to continual improvement and any changes needed to the ISMS. The exact inputs and outputs are set out in the standard for the applicable edition, so verify the current version's wording rather than relying on a fixed list.

Common misconceptions

Performance evaluation in ISO/IEC 27001 refers to reviewing the job performance of employees or security staff.
Clause 9 (Performance evaluation) concerns evaluating the performance and effectiveness of the information security management system itself, through monitoring and measurement, internal audit, and management review, not human resources appraisals of individuals.
Meeting ISO/IEC 27001 Clause 9 is equivalent to a SOC 2 examination of operating effectiveness.
The two are related in intent but distinct in mechanism. Clause 9 is part of the certifiable ISMS requirements assessed by an accredited certification body, while SOC 2 Type II operating-effectiveness testing is an attestation performed by a licensed CPA firm under SSAE 18. Mapping between them is partial, and satisfying one does not automatically satisfy the other.
A single internal audit or one management review satisfies Clause 9 permanently.
Clause 9 typically requires these activities to occur at planned intervals on an ongoing basis. The specific frequency and depth depend on the organization's audit programme, risk assessment, and scoping decisions rather than a fixed universal schedule.

Best practices

Define in advance what will be monitored and measured, the methods used, and the intervals for analysis and evaluation, so that results are meaningful and reproducible for the defined ISMS scope.
Establish and maintain an internal audit programme with defined criteria, scope, frequency, and reporting lines, and ensure auditors are objective with respect to the areas they audit.
Schedule management reviews at planned intervals and ensure top management considers the required inputs, such as audit results, monitoring outcomes, status of prior actions, and improvement opportunities.
Retain documented information as evidence of monitoring and measurement results, audit outcomes, and management review decisions, since certification bodies typically examine these records.
Feed the outputs of performance evaluation into nonconformity handling and continual improvement activities so that identified gaps are tracked to resolution.
Confirm that the metrics, audit scope, and review coverage align with the ISMS scope and Statement of Applicability, remembering that certification covers only the defined scope of the ISMS.