Frameworks / ISO 22301:2019 / 9.1 ISO 22301:2019
Performance evaluation, ISO 22301:2019
ISO 22301:2019 9.1: Monitoring, measurement, analysis and evaluation Determine what needs monitoring and measuring, the methods that will produce valid results, and when and by whom measurement is performed and when and by whom the results are analysed and evaluated; retain the results as documented evidence and use them to evaluate BCMS performance and effectiveness.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 84 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting NIST800-CA-7 CA-7 Continuous Monitoring NIST800-IR-5 IR-5 Incident Monitoring NIST800-PM-31 PM-31 Continuous Monitoring Strategy NIST800-PM-6 PM-6 Measures of Performance NIST800-SI-4 SI-4 System Monitoring NIST800-SR-10 SR-10 Inspection of Systems or Components SP800-53-CA Assessment, Authorization, and Monitoring Family NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved 5.22 Monitoring, review and change management of supplier services 5.36 Compliance with policies, rules and standards for information security 8.15 Logging 8.16 Monitoring activities 8.6 Capacity management 5.22 Monitoring, review and change management of supplier services 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.15 Logging 8.16 Monitoring activities SOC2-A1.1 A1.1 Managing processing capacity SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.8.4 12.8.4 Annual monitoring of TPSP compliance status CPS230-P30 Monitoring, Review and Testing of Control Effectiveness CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting CIS-17.9 Establish and Maintain Security Incident Thresholds CIS-8.11 Conduct Audit Log Reviews AU-6 Audit Record Review, Analysis, and Reporting CA-7 Continuous Monitoring AU-6 Audit Record Review, Analysis, and Reporting CA-7 Continuous Monitoring ISO30401-11 Monitoring, measurement, and analysis ISO30401-9.1 Monitoring, measurement, analysis, evaluation ISO-37002-9.1 Monitoring, measurement, analysis and evaluation ISO37002-9.1 Monitoring, Measurement, Analysis, Evaluation ISO-39001-9.1 Monitoring, measurement, analysis and evaluation ISO39001-9.1 Monitoring, Measurement, Analysis, and Evaluation ISO-41001-9.1 Monitoring, measurement, analysis and evaluation ISO41001-9.1 Monitoring, Measurement, Analysis, and Evaluation ISO-50001-9.1 Monitoring, measurement, analysis and evaluation of energy performance 9.1 Monitoring, measurement, analysis and evaluation of energy performance and the EnMS ISO-56002-9.1 Monitoring, measurement, analysis and evaluation ISO56002-9.1 Monitoring, measurement, analysis and evaluation 27003-9.1 Monitoring, Measurement, Analysis, Evaluation ISO27003-9.1 Monitoring, measurement, analysis and evaluation AS9100D-9.1 Monitoring, Measurement, Analysis, Evaluation AEO-13 Measurement, Analyses and Improvement C5-COM-04 Information on information security performance and management assessment of the ISMS CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems 9.1 Monitoring, measurement, analysis and evaluation 9.1 Monitoring, measurement, analysis and evaluation ISO-22313-9.1 Monitoring, measurement, analysis and evaluation 5.7.1 Monitoring, measurement, analysis and evaluation A.6.2 A.6.2 Monitoring and measurement 9.1 9.1 Monitoring, measurement, analysis and evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.1 Monitoring, measurement, analysis and performance evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.1 Monitoring, measurement, analysis and evaluation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Performance evaluation, ISO 22301:2019 You are reading one control. How much of ISO 22301:2019 have you already done? ISO 22301:2019 9.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.
Query this from an agent The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.