ISO 27001 · Domain 5
Performance Evaluation and Improvement
About 15% of the exam
Clause 9 in three parts
- 9.1
- monitoring, measurement, analysis, evaluation
- 9.1 decisions
- what, how, when and by whom
- 9.2.1
- internal audits at planned intervals
- 9.2.2
- the internal audit program itself
- 9.3.1
- review at planned intervals
- 9.3.2
- the required review inputs
- 9.3.3
- documented results of the review
Clause 9 is three activities, not one dashboard: measurement, internal audit and management review each need their own evidence
Monitoring versus measurement
- Monitoring
- watching status over time
- Measurement
- assigning a number to something
- Analysis
- explaining what the numbers show
- Evaluation
- judging results against a target
- Example
- firewall light versus blocked count
Clause 10 order in 2022
- 10.1
- continual improvement, stated first
- 10.2
- nonconformity and corrective action
- Change
- the two swapped since 2013
- Preventive action
- no separate clause remains
- Intent
- risk thinking absorbs prevention
Internal audit program
- Frequency reflects process importance
- Prior audit results shape coverage
- Methods, responsibilities and reporting defined
- Auditors objective and impartial
- Nobody audits their own work
- Results reported to relevant management
- Program and results retained as records
Designing a measure that works
- Tie every measure to an objective
- Prefer outcomes over activity counts
- Successful restore tests beat backup counts
- State the target before collecting data
- Name who analyzes it and when
- Trends matter more than single points
Corrective action sequence
- React and correct
- Contain the immediate effect
- Find the real cause
- Check elsewhere for the same issue
- Act on the cause
- Review effectiveness
- Update risks if needed
- Record everything
Closing an action on schedule is not the same as eliminating the cause
Findings and how they are graded
- Major
- a requirement is not met
- Major example
- no management review has happened
- Minor
- isolated lapse, process still works
- Minor example
- one access review record unsigned
- Observation
- concern short of a nonconformity
- Opportunity
- suggestion carrying no obligation
- Consistency
- grading must travel between auditors
A single lapse inside a working process is minor; a process that never happens at all is major
The certification cycle
- Stage 1 readiness
- Stage 2 implementation
- Certification decision
- Surveillance year one
- Surveillance year two
- Recertification
- Stage 1
- documentation and readiness review
- Stage 2
- evidence the ISMS actually operates
- Decision
- made by an independent reviewer
- Certificate
- valid for three years
- Surveillance
- at least once each year
- Recertification
- whole system before expiry
- Transfer
- moving to another accredited body
Records clauses 9 and 10 demand
- Monitoring and measurement results
- Internal audit program and results
- Management review documented results
- Nature of each nonconformity
- Actions taken and their results
- Evidence retained, not merely claimed
Improvement failures
- Same nonconformity keeps coming back
- Cause analysis stops at the symptom
- Effectiveness judged by task completion
- Only corrective, never proactive improvement
- Improvements with no owner stall silently
- Dashboard treated as all of clause 9
Root cause techniques
- Five whys drills past the symptom
- Fishbone groups causes by category
- Fault tree works back from failure
- Recurrence means the analysis was wrong
- Escalate to a different technique
Rapid recall: who does what
- Internal auditor
- checks conformity inside the organization
- Lead auditor
- runs the certification audit team
- Certification body
- employs auditors and issues certificates
- Decision reviewer
- independent of the audit team
- Accreditation body
- oversees the certification body
- Top management
- reviews results and funds improvement
Reference strip: measure, audit, review, correct, certify
Measure
- Decide what, how, when, who
- Outcome measures beat activity counts
- Analysis and evaluation both recorded
Audit
- Program driven by importance
- Impartial auditors, no self review
- Findings reported to management
Review
- Planned intervals, required inputs
- Improvement and change decisions
- Minutes retained as evidence
Correct
- Correction then cause elimination
- Check for the same issue elsewhere
- Effectiveness verified afterwards
Certify
- Stage 1 then stage 2
- Three year certificate, annual surveillance
- Recertification covers the whole ISMS
Quick exam traps
- Trap: A metrics dashboard alone satisfies clause 9
- Trap: Completing a corrective action on time proves it was effective
- Trap: Any nonconformity found at surveillance means the certificate is withdrawn
- Trap: Preventive action is still a separate requirement in the 2022 edition
- Trap: An internal auditor may audit the process they run
- Trap: Stage 1 is where the certification decision is made
- Trap: One missing signature in a working process is a major nonconformity
cybercertprep.com · original revision sheet written from the public body of knowledge