ISO/IEC 27004:2016 provides guidance to help organizations evaluate the performance and effectiveness of an implemented ISMS (information security management system), as mandated in section 9.1 of ISO/IEC 27001:2013.
The results of monitoring and measurement can support decisions relating to ISMS governance, management, operational effectiveness, and continual improvement.
In order to be considered valid under ISO 27001, the methods chosen for monitoring, measurement, analysis, and evaluation “should produce comparable and reproducible results”.
ISO/IEC 27004:2016 cancels and replaces ISO/IEC 27004:2009, which has been technically revised.
The Standard has been totally restructured to reflect its new purpose providing guidance on section 9.1 of ISO/IEC 27001:2013, which did not exist when ISO 27004:2009 was published.
The concepts and processes have been modified and expanded. However, the theoretical foundation (ISO/IEC 15939) remains the same and several of the examples given in the previous edition have been preserved, albeit updated.
ISO 27004 is applicable to all types and sizes of organization but, as with other ISO/IEC 27000-series standards, it should be used according to each organization’s specific situation.