ISO/IEC 27004:2016
Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation. Provides guidance to assist organizations in evaluating information security performance and effectiveness of the ISMS. Supports ISO 27001 Clause 9.1 requirements.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Alignment
| Code | Title |
|---|---|
| 27004-5.2 | Fulfilling 27001 Requirements |
Annex A: Information Security Measurement Model
| Code | Title |
|---|---|
| 27004-A.1 | Coverage Measures |
| 27004-A.2 | Patching and Vulnerability Measures |
| 27004-A.3 | Incident Measures |
Annex B: Example Measurements
| Code | Title |
|---|---|
| 27004-B.1 | Example measurement definitions |
| 27004-B.2 | Control effectiveness examples |
| 27004-B.3 | Process performance examples |
Annex Examples
| Code | Title |
|---|---|
| 27004-A.1 | Coverage Measures |
| 27004-A.2 | Patching and Vulnerability Measures |
| 27004-A.3 | Incident Measures |
| 27004-A.4 | Awareness and Training Measures |
| 27004-A.5 | Access Control Measures |
| 27004-A.6 | Third-Party Measures |
Clause 1-4: Introductory Clauses
| Code | Title |
|---|---|
| 27004-1 | Scope |
| 27004-2 | Normative references |
| 27004-3 | Terms and definitions |
| 27004-4 | Structure and overview |
Clause 5: Monitoring, Measurement, Analysis and Evaluation Rationale
| Code | Title |
|---|---|
| 27004-5.1 | Need for Measurement |
| 27004-5.2 | Fulfilling 27001 Requirements |
| 27004-5.3 | Validity of Results |
Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation
| Code | Title |
|---|---|
| 27004-6.1 | What to Monitor and Measure |
| 27004-6.2 | Who to Monitor and Measure |
| 27004-6.3 | When to Monitor and Measure |
| 27004-6.4 | How to Monitor and Measure |
Clause 7: Types of Measures
| Code | Title |
|---|---|
| 27004-7.1 | Performance Indicators |
| 27004-7.2 | Effectiveness Indicators |
| 27004-7.3 | Measurement Construct |
Clause 8: Processes
| Code | Title |
|---|---|
| 27004-8.1 | Data Collection |
| 27004-8.2 | Analysis |
| 27004-8.3 | Evaluation of measures |
| 27004-8.4 | Review and improvement of processes |
Constructs
| Code | Title |
|---|---|
| 27004-7.1 | Performance Indicators |
| 27004-7.2 | Effectiveness Indicators |
| 27004-7.3 | Measurement Construct |
Evaluation
| Code | Title |
|---|---|
| 27004-9.1 | Evaluation of Results |
Improvement
| Code | Title |
|---|---|
| 27004-10.1 | Programme Review and Improvement |
Operation
| Code | Title |
|---|---|
| 27004-8.1 | Data Collection |
| 27004-8.2 | Analysis |
Programme Design
| Code | Title |
|---|---|
| 27004-6.1 | What to Monitor and Measure |
| 27004-6.2 | Who to Monitor and Measure |
| 27004-6.3 | When to Monitor and Measure |
| 27004-6.4 | How to Monitor and Measure |
Quality
| Code | Title |
|---|---|
| 27004-5.3 | Validity of Results |
Rationale
| Code | Title |
|---|---|
| 27004-5.1 | Need for Measurement |
Reporting
| Code | Title |
|---|---|
| 27004-9.2 | Communication and Reporting |
Your Compliance Coverage
If you comply with ISO/IEC 27004:2016, you already cover:
ISO/IEC 27557:2022 — Organisational Privacy Risk Management
10%
3 controls mapped
Compare →ISO/IEC 23837 — Security Requirements for Quantum Key Distribution
10%
3 controls mapped
Compare →SQF Code Edition 9 — Safe Quality Food
10%
3 controls mapped
Compare →+ 415 more: PCI DSS 4.0 (10%), BRCGS Global Standard for Food Safety Issue 9 (10%)
See all 418 mapped frameworks ↓Maps to 418 other frameworks
Frequently Asked Questions
What is ISO/IEC 27004:2016?
ISO/IEC 27004:2016 is a compliance framework from International with 17 domains and 45 controls. Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation. Provides guidance to assist organizations in evaluating information security performance and effectiveness of the ISMS. Supports ISO 27001 Clause 9.1 requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27004:2016 have?
ISO/IEC 27004:2016 has 45 controls organised across 17 domains. The largest domains are Annex Examples (6 controls), Clause 1-4: Introductory Clauses (4 controls), Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27004:2016 map to?
ISO/IEC 27004:2016 maps to 418 other compliance frameworks. The top mapping partners are ISO/IEC 27557:2022 — Organisational Privacy Risk Management (10% coverage), ISO/IEC 23837 — Security Requirements for Quantum Key Distribution (10% coverage), SQF Code Edition 9 — Safe Quality Food (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27004:2016 compliance?
Start your ISO/IEC 27004:2016 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27004:2016 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required