The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to
assign the responsibility to the information security team.
assign the responsibility to the team responsible for the management of the controls.
create operational reports on the effectiveness of the controls.
perform an independent audit of the security controls.
Submit