Skip to main content
Informationssicherheit / NIS2

ISMS metrics

ISMS metrics are defined measures an organisation uses to monitor and evaluate the performance and effectiveness of its information security management system and to report on it to top management on a regular basis.

ISMS metrics – often referred to as security KPIs – provide the quantitative basis for measuring whether an information security management system actually works. Clause 9.1 of ISO/IEC 27001:2022 requires an organisation to determine what needs to be monitored and measured, by which methods, when the measurement is taken and evaluated, and who is responsible for each step; the results must be retained as documented information. A useful distinction is between performance measures, which describe how the ISMS is operated (coverage rates, processing times), and effectiveness indicators, which show whether a control genuinely reduces risk. ISO/IEC 27004 supplies the methodology, separating base measures, derived measures and the indicators built from them, each with a target value and a threshold.

Meaningful metrics come from what the organisation wants to steer, not from whatever a tool happens to export. A sound metrics set is therefore derived from the protection objectives, the risk assessment and the agreed risk treatment measures; it can be collected reproducibly from existing sources; and every measure has a named owner and a defined target range. Proven examples include adherence to patch deadlines for critical vulnerabilities, the share of open vulnerabilities past the agreed remediation window, mean time to detect and mean time to contain security incidents, multi-factor authentication coverage, the click rate in phishing simulations, the proportion of risk treatment actions closed on time, and the number of overdue audit findings. Pure activity counts with no link to risk – the volume of blocked spam, for instance – fill report pages but give management nothing to decide on.

Metrics only fulfil their purpose once they reach the governing body. Under clause 9.3 of ISO/IEC 27001:2022, monitoring and measurement results, audit results, the status of corrective actions and feedback from interested parties are mandatory inputs to the management review, which must produce documented decisions on improvements and resources – closing the loop of the PDCA cycle. The EU NIS2 Directive (EU) 2022/2555 adds regulatory weight: Article 21(2)(f) explicitly calls for policies and procedures to assess the effectiveness of cybersecurity risk management measures, and Article 20 makes management bodies personally responsible for approving and overseeing them. Germany implements this through the NIS2 implementation act (NIS2UmsuCG), which transfers the obligations into the recast BSIG; because the German transposition was delayed and parts of it have been refined since, the precise point at which individual duties and registration procedures apply should always be verified against the current statute and the BSI's published guidance. The practical consequence is that metrics are not an end in themselves – they are the evidence that management is in a position to exercise its oversight duty at all.

Legal Basis

ISO/IEC 27001:2022 clauses 9.1 and 9.3; ISO/IEC 27004; Art. 20 and Art. 21(2)(f) NIS2 Directive (EU) 2022/2555 (transposed in Germany via the NIS2UmsuCG into the BSIG); BSI Standard 200-1 (performance review and management review)

Practical Example

The information security officer of a mid-sized mechanical engineering company is asked to report quarterly to the executive board on whether the ISMS is working. Instead of a 30-page tool export, she defines seven metrics along the highest assessed risks: patch deadline adherence for internet-facing systems, share of critical vulnerabilities older than 14 days, MFA coverage across all administrative accounts, mean time to detect and to contain security incidents, phishing simulation click rate, share of risk treatment actions completed on schedule, and the number of overdue audit findings. Each metric is given an owner, a data source, a target value and an escalation threshold. In the second quarter it becomes apparent that MFA coverage for the service accounts of an external maintenance provider stays persistently below target; in the management review the board therefore approves budget for a privileged access management solution and tighter contractual requirements in supplier management. The decision, the underlying metric and the implementation status are documented and later serve as evidence of performance evaluation in the certification audit.

FAQ

No. Clause 9.1 only requires the organisation itself to determine what is measured, by which methods, when and by whom, and to retain the results as documented information. Neither a count nor specific metrics are mandated. Auditors will, however, check whether the chosen metrics fit the organisation's risks and objectives and whether they actually lead to decisions.
There is no fixed frequency. The management review under clause 9.3 must take place at planned intervals – in practice usually once a year, supplemented by shorter quarterly or half-yearly reporting to the leadership. Organisations in scope of NIS2 are well advised to report more frequently, because management bodies are required to oversee the risk management measures on an ongoing basis.
A performance measure describes how well a process is run – the number of training sessions delivered or the time taken to close tickets. An effectiveness indicator shows whether the underlying security objective is being met, such as a falling click rate in phishing simulations or a shorter time to contain incidents. For the management review, effectiveness indicators carry far more meaning.

How preeco supports you

Learn how our software supports you with this topic.

Learn more