ISO/IEC 27004
E472704
ISO/IEC 27004 is an international standard that provides guidelines for measuring and evaluating the effectiveness of an information security management system (ISMS) within the ISO/IEC 27000 family.
All labels observed (1)
| Label | Occurrences |
|---|---|
| ISO/IEC 27004 canonical | 2 |
Statements (38)
| Predicate | Object |
|---|---|
| instanceOf |
information security standard
ⓘ
international standard ⓘ |
| aimsTo |
enable organizations to assess ISMS performance
ⓘ
support continual improvement of ISMS ⓘ |
| alignedWith | Plan-Do-Check-Act cycle ⓘ |
| appliesTo | information security management system ⓘ |
| belongsToSeries | ISO/IEC 27000-series standards NERFINISHED ⓘ |
| contributesTo |
evidence-based information security management
ⓘ
risk-based decision making in information security ⓘ |
| defines |
criteria for evaluating ISMS effectiveness
ⓘ
processes for information security measurement ⓘ requirements for information security metrics ⓘ |
| field |
information security
ⓘ
information security management ⓘ |
| focusesOn |
effectiveness of an information security management system
ⓘ
evaluation of information security performance ⓘ measurement of information security ⓘ |
| hasScope |
measurement of ISMS outcomes
ⓘ
measurement of ISMS processes ⓘ measurement of information security controls ⓘ |
| partOf | ISO/IEC 27000 family NERFINISHED ⓘ |
| provides |
guidelines for analysis of ISMS performance
ⓘ
guidelines for evaluation of ISMS effectiveness ⓘ guidelines for improvement of ISMS ⓘ guidelines for information security measurement ⓘ guidelines for monitoring ISMS performance ⓘ |
| publishedBy |
International Electrotechnical Commission
NERFINISHED
ⓘ
International Organization for Standardization ⓘ |
| relatedTo | ISO/IEC 27001 NERFINISHED ⓘ |
| supportsImplementationOf | ISO/IEC 27001 NERFINISHED ⓘ |
| targetAudience |
ISMS auditors
ⓘ
governance and compliance professionals ⓘ information security managers ⓘ risk managers ⓘ |
| usedBy | organizations implementing ISO/IEC 27001 ⓘ |
| usedFor |
designing information security metrics
ⓘ
implementing information security measurement processes ⓘ reporting on information security performance ⓘ |
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.