Clause 9 is where ISMS schedules most often break. Once the procedures and the Statement of Applicability are finished, it feels like only the audit remains — but certification requires records of one completed cycle of internal audit and management review. You cannot present for audit with documents alone.
Clause 9 also has internal dependencies. Without monitoring results there is little for an internal audit to examine; without audit results the management review inputs are empty. Three activities have to run in sequence, and the time for that has to be reserved by working backwards from the audit date.
This article sets out the three activities required by clause 9 (Performance evaluation), separating design decisions from how auditors examine them. "What to measure" and "auditor independence" get extra attention, because they are where small organisations get stuck.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
What Clause 9 Asks For
Three subclauses, and it helps to read them as evaluation getting progressively coarser as the decision-maker gets more senior.
| Subclause | Activity | Who performs it | Output |
|---|---|---|---|
| 9.1 Monitoring, measurement, analysis and evaluation | Measure the agreed indicators continuously; analyse and evaluate the results | Operating departments | Measurement results with evaluation |
| 9.2 Internal audit | Audit whether the ISMS conforms to the standard and to your own requirements, and is effectively implemented and maintained | Auditors independent of the area audited | Audit report, nonconformities and observations |
| 9.3 Management review | Evaluate the ISMS's continuing suitability, adequacy, and effectiveness from defined inputs | Top management | Improvement opportunities, decisions to change the ISMS |
Clause 8 executes, clause 9 checks, clause 10 fixes — the C and A of the cycle. See Clause 4: Context, Clause 5: Leadership, Clause 6: Planning, Clause 7: Support, Clause 8: Operation, and the overview in What Is an ISMS.
9.1 — what, how, when, who
9.1 asks you to determine and document:
- what is monitored and measured (which ISMS processes and controls)
- by what methods — and the methods must produce comparable and reproducible results
- when measurement is performed
- who performs it
- when and by whom the results are analysed and evaluated
The last item is the one that gets dropped. If you do not separately name who evaluates, you end up collecting numbers nobody reads.
9.2 — auditor independence
Internal audit confirms two things: that the ISMS conforms to the standard and to your own requirements, and that it is effectively implemented and maintained. The core requirement is auditor objectivity and impartiality — in practice, not auditing your own work.
Audits are also planned as a programme, not as one-off events: frequency, methods, responsibilities, planning requirements, and reporting, taking into account the importance of the processes concerned and the results of previous audits.
9.3 — management review inputs
Top management performs the review at planned intervals. The standard enumerates the inputs, and dropping even one of them is a common route to a nonconformity. The table below serves as a template.
What You Actually Produce
| Subclause | Artefact | Key points |
|---|---|---|
| 9.1 | Monitoring and measurement plan (subject, method, frequency, performer, evaluator) | Map one-to-one against information security objectives; never leave an objective without a method |
| 9.1 | Measurement records with evaluation comments | Do not leave bare numbers — add a line judging performance against the target |
| 9.2 | Internal audit programme (annual plan) | State scope, frequency, auditor assignment, and how independence is secured |
| 9.2 | Audit checklist | Cover the clauses and the controls marked applicable in the SoA; reuse is fine, but add last year's findings |
| 9.2 | Internal audit report | Record conformities too; for nonconformities state the fact, the evidence, and the requirement, then hand off to corrective action |
| 9.3 | Management review minutes | Use a format with a field per required input; name attendees and decisions |
See Running an Internal Audit and Management Review in Practice.
Never set an objective you cannot measure
Objectives (clause 6) and indicators (clause 9) should be designed together. Set objectives first and bolt measurement on afterwards, and you will always be left with something unmeasurable.
| Poor objective | Why it cannot be measured | Measurable rewrite |
|---|---|---|
| Raise employee security awareness | "Awareness" has no observable | 100% completion of annual training; 95% scoring 80+ on the comprehension test |
| Zero incidents | Cannot distinguish success from luck, and suppresses reporting | Mean time from detection to first report under two hours |
| Strengthen security | No subject, no threshold | 90%+ of critical and high vulnerabilities remediated within 14 days of detection |
| Manage suppliers appropriately | No definition of "appropriate" | 100% annual check sheet return rate; zero overdue |
Set targets at a level that is achievable with effort. Carrying a permanently missed target means explaining the same thing at every review, which actually stalls improvement. See Setting Security Objectives and KPIs.
Where It Goes Wrong
1. A small organisation cannot achieve auditor independence
At 20–30 people, the person who runs IT is usually also the ISMS secretariat. If they audit their own area, independence fails.
Three realistic options:
| Approach | Precondition | Watch out for |
|---|---|---|
| Cross-audit between departments | Two or more genuinely independent areas exist | Reciprocal leniency; make the checklist strict |
| Management or corporate functions audit | They are uninvolved in the work audited | Technical depth suffers; pair with external help for technical areas |
| Use external auditors | Budget exists | Check whether the internal audit manager role can also be outsourced |
The standard requires internal appointment for top management and the ISMS manager and officers; the internal audit manager and auditors can be outsourced. For small organisations this is usually the most practical route. See ISMS for Small Organisations.
2. The audit becomes a document-existence check
A checklist that only asks "does the procedure exist?" finishes in thirty minutes and finds nothing. That does not verify effectiveness.
Effectiveness requires sampling a record and tracing it: "Show me three access grant requests. Who approved them, and when were leavers' permissions revoked?" At that depth, divergence from reality becomes visible.
3. Zero nonconformities in the internal audit
An organisation whose first internal audit finds nothing is sometimes told at the certification audit that its internal audit is not functioning — a freshly built ISMS with no defects is implausible.
Raising nonconformities is the internal audit working, not failing. Records of finding and correcting them are the evidence that the mechanism turns.
4. Management review inputs go missing
There are many required inputs, and without a field per item in the minutes template, something is always dropped. Use this as the template.
| Input | Typical content | Risk of omission |
|---|---|---|
| Status of actions from previous reviews | Implementation status and reasons for open items | Medium |
| Changes in external and internal issues relevant to the ISMS | Business change, revised laws and guidelines, reorganisation | High |
| Changes in needs and expectations of interested parties | Customer requirements, client demands, regulatory direction | Highest (made explicit in the 2022 edition) |
| Nonconformities and corrective actions | Counts and status from audits, certification audits, incidents | Low |
| Monitoring and measurement results | Actuals for the 9.1 indicators | Low |
| Audit results | Internal audits and external audits including surveillance | Low |
| Fulfilment of information security objectives | Met/missed per objective, with causes | Medium |
| Feedback from interested parties | Customer findings, queries raised in check sheet responses | High |
| Results of risk assessment and status of the risk treatment plan | Latest assessment, residual risk, treatment progress | Medium |
| Opportunities for continual improvement | Improvement proposals, next-period priorities | Medium |
Do not forget the outputs. A management review produces opportunities for continual improvement and decisions on changes to the ISMS. Minutes that record only "a report was received," with no decisions, are judged not to be a review.
5. Sequencing and timing
Run the internal audit immediately before the certification audit and there is no time to correct findings. Run it too early and changes made afterwards go unverified.
In practice, internal audit six to eight weeks before the stage 2 audit, with management review two to three weeks later works well, leaving room for corrective action and effectiveness verification. See The ISMS Timeline.
What Auditors Look At
| Focus | Typical question | Preparation |
|---|---|---|
| Measurement design | "How is this indicator measured? Would anyone calculating it get the same number?" | Write the method down as a procedure; be able to show the source data |
| Link to objectives | "Where can I see performance against this objective?" | Cross-reference the objectives register and the measurement records |
| Auditor independence | "Is this auditor involved in the area they audited?" | State independence arrangements in the programme; show the contract if outsourced |
| Audit coverage | "In which cycle are the controls marked applicable in the SoA audited?" | Show an annual or three-year coverage plan |
| Audit depth | "What evidence produced this finding?" | Record the identifiers of the evidence examined in the report |
| Who performed the review | "Did top management attend?" | Minutes should show executive attendance; if absent, show alternative involvement |
| Review decisions | "What was decided here, and was it done?" | Number the decisions and report their status at the next review |
Stage 1 examines plans and formats; stage 2 examines execution and depth. See What Stage 1 Audits Examine, What Stage 2 Audits Examine, and Common Nonconformities.
Healthcare Examples
Include indicators specific to medical information
Alongside general IT metrics, indicators tied to how medical information is handled double as material for answering customer questions.
| Example indicator | Method | Frequency |
|---|---|---|
| Privileged access sessions to production holding medical information, and approval rate | IdP or bastion log aggregation | Monthly |
| On-time response rate to security enquiries from customer hospitals | Enquiry register | Quarterly |
| Annual assessment completion rate for suppliers (cloud, maintenance) | Supplier register | Annual |
| Restore-test success rate from backups | Restore test records | Half-yearly |
| 14-day remediation rate for critical and high vulnerabilities | Vulnerability management tool | Monthly |
Audit three-ministry guideline compliance in the same pass
If you serve hospitals, running the ISMS internal audit and guideline compliance checks separately doubles the effort. Merging guideline-derived items into the audit checklist produces evidence for both in one pass. See Integrating ISMS Documents with the Three-Ministry Guidelines and Japan's Three-Ministry Guidelines.
Feed changing customer requirements into the review
"Changes in the needs and expectations of interested parties" is the most-missed input, and healthcare companies have concrete material for it: changes in the questions on security check sheets from customer hospitals, new requirements added to procurement specifications, findings raised in hospital-side audits. See Security Check Sheets for Vendors for the buyer's view.
Turn log review into an indicator
Collecting access logs and reviewing them are different things. Including the review completion rate among your 9.1 indicators keeps the practice from becoming nominal. See Reviewing EMR Access Logs.
Conclusion
- Certification requires records of one completed cycle of internal audit and management review — documents alone are not enough
- 9.1 covers what, how, when, and who, plus who evaluates the results and when. Separate the measurer from the reviewer
- Never set an objective you cannot measure. Design objectives and methods together
- Internal audit turns on not auditing your own work. Small organisations can outsource the audit manager and auditors
- Finding nonconformities is the audit succeeding. A run of zeroes invites scrutiny
- Give the management review a field per required input — "changes in interested parties' needs and expectations" is the most commonly missed
- Place the internal audit six to eight weeks before stage 2, leaving time for correction and verification
Pottech supports ISMS certification with a focus on healthcare: designing measurement indicators, building the internal audit programme, and facilitating the management review. We can serve as your internal audit manager and internal auditors — which matters most for small organisations struggling with independence.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Japanese Industrial Standards Committee
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and the handling of certification are governed by the standard itself and by the publications of accreditation and certification bodies. Audit practice varies between bodies and auditors.