Monitoring, internal audit and management review
Clause 9 requires organizations to evaluate the effectiveness of their Information Security Management System (ISMS). This is achieved through continuous performance monitoring, periodic formal internal audits, and structured management reviews to ensure the system achieves its intended outcomes.
What it means
The intent of this clause is to move from "implementation" to "verification." It ensures that security controls are not just documented on paper but are functioning as intended in a live environment. This creates a feedback loop where data informs leadership about what is working and what needs adjustment.
In practice, this involves three distinct layers: operational monitoring (real-time or frequent checks), tactical auditing (periodic deep dives into compliance), and strategic review (top management oversight). Together, these activities provide the evidence needed to prove the ISMS is mature and improving over time.
How to meet it
- Define specific security metrics and Key Performance Indicators (KPIs) that indicate whether your controls are effective (e.g., percentage of patched systems or number of unauthorized access attempts).
- Establish a monitoring schedule identifying who is responsible for measuring these KPIs and how often the data is analyzed.
- Develop an internal audit program that defines the frequency, methods, and responsibilities for auditing all areas of the ISMS over a set cycle.
- Conduct internal audits using impartial evaluators—either trained staff members not responsible for the area being audited or external third-party consultants.
- Schedule formal management review meetings at planned intervals with an agenda covering required inputs such as audit results, feedback from interested parties, and risk assessment updates.
- Document the outputs of management reviews, specifically focusing on decisions regarding resource allocation and necessary changes to the ISMS.
Evidence an auditor asks for
- Performance reports or dashboards showing tracked security metrics and analysis of trends.
- An internal audit schedule/plan and the resulting detailed audit reports.
- Minutes from management review meetings, including a list of attendees and specific action items decided upon.
- Records of corrective actions taken to address non-conformities discovered during audits or monitoring.
Common pitfalls
- Lack of objectivity: Using the same person to implement a control and then perform the internal audit for that same control.
- Superficial reviews: Holding management review meetings that are "rubber stamp" exercises without documenting actual analysis, challenges, or strategic decisions.
- Data collection without action: Gathering vast amounts of monitoring data (logs/metrics) but failing to analyze it or use it to trigger improvements.