ISO/IEC 27001:2022 Clause 9.1 – Monitoring, measurement, analysis, and evaluation:
“The organization shall evaluate the performance and effectiveness of the information security management system. The evaluation shall include... comparison against performance indicators and security objectives.”
The purpose is to ensure that security objectives (Clause 6.2) are being met. Measuring performance allows organizations to determine whether controls and processes are effective and aligned with strategic goals.
Option A is too narrow, and Option C is incorrect because manual tracking may still be required in some cases.
[References:, ISO/IEC 27001:2022 Clause 6.2 and 9.1, ISO/IEC 27004:2016 – Clause 7.2 (Use of metrics for objective evaluation)===========, , ]
Submit