Standard

BS ISO/IEC 27004:2016 - TC

Information technology. Security techniques. Information security management. Monitoring, measurement, analysis and evaluation

Current, Under Review

Published:

What is ISO/IEC 27004 about?  

ISO/IEC 27004 discusses security techniques. ISO/IEC 27004 provides guidelines intended to assist organizations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfill the requirements of ISO/IEC 27001:2013, 9.1. ISO/IEC 27004 helps to develop and operate measurement processes, and how to assess and report the results of the associated measurement constructs. ISO/IEC 27004 establishes:  

  • The monitoring and measurement of information security performance 
  • The monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls 
  • The analysis and evaluation of the results of monitoring and measurement 

Who is ISO/IEC 27004for? 

ISO/IEC 27004 on information security management system is useful for: 

  • All organizations 

Why should you use ISO/IEC 27004 

The objective of an information security management system (ISMS) is the preservation of confidentiality, integrity, and availability of information. There are information security management system (ISMS) activities that concern the planning of how to do this, and the implementation of those plans. However, by themselves, these activities cannot guarantee that the realisation of those plans fulfills the information security objectives. Therefore, in the ISMS as defined by ISO/IEC 27001, there are several requirements to evaluate if the plans and activities ensure the fulfillment of the information security objectives. 

 ISO/IEC 27004 shows how to construct an information security measurement program, how to select what to measure, and how to operate the necessary measurement processes. ISO/IEC 27004 includes extensive examples of different types of measures, and how the effectiveness of these measures can be assessed. A successful measurement program built using ISO/IEC 27004 will meet the performance monitoring requirements set out in ISO/IEC 27001

What’s changed since the last update?  

BS ISO/IEC 27004:2016 cancels and replaces BS ISO/IEC 27004:2009. BS ISO/IEC 27004:2016 includes the following principal changes: 

  • Atotal restructuring of the document because it has a new purpose – to provide guidance on ISO/IEC 27001:2013, 9.1 
  • The concepts and processes have been modified and expanded. However, the theoretical foundation (ISO/IEC 15939) remains the same and several of the examples given in the BS ISO/IEC 27004:2009 are preserved, albeit updated  
Product Details
Descriptors
Measurement
Data analysis
Computers
Performance testing
Anti-burglar measures
Data processing
Quality auditing
Data security
Verification
Management
Data storage protection
ICS Codes
35.030 IT Security
Committee
IST/33/1
International relationships
Identical to:

ISO/IEC 27004:2016

ISBN
978-0-539-08360-6
Publisher
BSI