ISO 22301:2019
Performance evaluation, ISO 22301:2019

ISO 22301:2019 9.1: Monitoring, measurement, analysis and evaluation

Determine what needs monitoring and measuring, the methods that will produce valid results, and when and by whom measurement is performed and when and by whom the results are analysed and evaluated; retain the results as documented evidence and use them to evaluate BCMS performance and effectiveness.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 84 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

  • NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting
  • NIST800-CA-7 CA-7 Continuous Monitoring
  • NIST800-IR-5 IR-5 Incident Monitoring
  • NIST800-PM-31 PM-31 Continuous Monitoring Strategy
  • NIST800-PM-6 PM-6 Measures of Performance
  • NIST800-SI-4 SI-4 System Monitoring
  • NIST800-SR-10 SR-10 Inspection of Systems or Components
  • SP800-53-CA Assessment, Authorization, and Monitoring Family
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

ISO 27001:2022 · 5 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.6 Capacity management

ISO 27002:2022 · 5 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.15 Logging
  • 8.16 Monitoring activities

SOC 2 · 5 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

CMMC 2.0 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting

CIS Controls v8 · 2 controls

  • CIS-17.9 Establish and Maintain Security Incident Thresholds
  • CIS-8.11 Conduct Audit Log Reviews

FedRAMP High · 2 controls

  • AU-6 Audit Record Review, Analysis, and Reporting
  • CA-7 Continuous Monitoring

FedRAMP Moderate · 2 controls

  • AU-6 Audit Record Review, Analysis, and Reporting
  • CA-7 Continuous Monitoring

HIPAA Security Rule · 2 controls

ISO 30401 · 2 controls

  • ISO30401-11 Monitoring, measurement, and analysis
  • ISO30401-9.1 Monitoring, measurement, analysis, evaluation
  • ISO-37002-9.1 Monitoring, measurement, analysis and evaluation
  • ISO37002-9.1 Monitoring, Measurement, Analysis, Evaluation
  • ISO-39001-9.1 Monitoring, measurement, analysis and evaluation
  • ISO39001-9.1 Monitoring, Measurement, Analysis, and Evaluation
  • ISO-41001-9.1 Monitoring, measurement, analysis and evaluation
  • ISO41001-9.1 Monitoring, Measurement, Analysis, and Evaluation
  • ISO-50001-9.1 Monitoring, measurement, analysis and evaluation of energy performance
  • 9.1 Monitoring, measurement, analysis and evaluation of energy performance and the EnMS

ISO 56002 · 2 controls

  • ISO-56002-9.1 Monitoring, measurement, analysis and evaluation
  • ISO56002-9.1 Monitoring, measurement, analysis and evaluation

ISO/IEC 27003:2017 · 2 controls

  • 27003-9.1 Monitoring, Measurement, Analysis, Evaluation
  • ISO27003-9.1 Monitoring, measurement, analysis and evaluation

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • AS9100D-9.1 Monitoring, Measurement, Analysis, Evaluation
  • AEO-13 Measurement, Analyses and Improvement

C5 (Germany) · 1 control

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

ISO 14001:2015 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 22000:2018 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation
  • ISO-22313-9.1 Monitoring, measurement, analysis and evaluation

ISO 27701:2019 · 1 control

  • 5.7.1 Monitoring, measurement, analysis and evaluation

ISO 28002:2011 · 1 control

  • A.6.2 A.6.2 Monitoring and measurement

ISO 37001:2016 · 1 control

  • 9.1 9.1 Monitoring, measurement, analysis and evaluation

ISO 37301:2021 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 45001:2018 · 1 control

  • 9.1 Monitoring, measurement, analysis and performance evaluation

ISO 55001:2014 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 9001:2015 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO/IEC 42001:2023 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Performance evaluation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 9.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.