The primary purpose of comparing actual performance against targets is to assess whether security objectives are being met. This is a direct requirement of ISO/IEC 27001:2022, Clause 9.1, which mandates monitoring, measurement, analysis, and evaluation to determine if objectives are achieved and to support continual improvement.
“The organization shall evaluate the performance and the effectiveness of the information security management system... and compare results with the objectives set.”
— ISO/IEC 27001:2022, Clause 9.1
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit