ISO/IEC 27004:2016 Preview

Information technology -- Security techniques -- Information security management -- Monitoring, measurement, analysis and evaluation

ISO/IEC 27004:2016 provides guidelines intended to assist organizations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes:

a) the monitoring and measurement of information security performance;

b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls;

c) the analysis and evaluation of the results of monitoring and measurement.

ISO/IEC 27004:2016 is applicable to all types and sizes of organizations.

General information

  • Status :  Published
    Publication date : 2016-12
  • Edition : 2
    Number of pages : 58
  • :
    ISO/IEC JTC 1/SC 27
    Information security, cybersecurity and privacy protection
  • 03.100.70
    Management systems
    IT Security

Buy this standard

Format Language
  • CHF178

Life cycle

A standard is reviewed every 5 years

Revisions / Corrigenda

You may be interested in:

By Elizabeth Gasiorowski-Denis on
How to measure the effectiveness of information security
You simply can’t be too careful when it comes to information security. Protecting personal records and commercially sensitive information is critical. But how can you tell that your ISO/IEC 27001 information security management system (ISMS) is making a difference? A new ISO/IEC International Standard...

Got a question?

Check out our FAQs

Customer care
+41 22 749 08 88

Opening hours:
Monday to Friday - 09:00-12:00, 14:00-17:00 (UTC+1)

Keep up to date with ISO

Sign up to our newsletter for the latest news, views and product information