ISO/IEC 27004:2016
Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation. Provides guidance to assist organizations in evaluating information security performance and effectiveness of the ISMS. Supports ISO 27001 Clause 9.1 requirements.
ISO/IEC 27004:2016 is a compliance framework from International with 10 domains and 30 controls that map to 171 other frameworks. The largest domains are Annex Examples (6 controls), Clause 1-4: Introductory Clauses (4 controls), Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Annex B: Example Measurements
Annex Examples
Clause 1-4: Introductory Clauses
| Code | Title |
|---|---|
| 27004-4 | Structure and overview |
Clause 5: Monitoring, Measurement, Analysis and Evaluation Rationale
Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation
Clause 7: Types of Measures
Clause 8: Processes
Evaluation
| Code | Title |
|---|---|
| 27004-9.1 | Evaluation of Results |
Improvement
| Code | Title |
|---|---|
| 27004-10.1 | Programme Review and Improvement |
Reporting
| Code | Title |
|---|---|
| 27004-9.2 | Communication and Reporting |
Your Compliance Coverage
If you comply with ISO/IEC 27004:2016, you already cover:
ISO 37001:2016
7%
2 controls mapped
Compare →WCAG 2.2
7%
2 controls mapped
Compare →W3C Verifiable Credentials (VC) Data Model 2.0
7%
2 controls mapped
Compare →+ 168 more: Vietnam Law on Cybersecurity (No. 24/2018/QH14) (7%), USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) (7%)
See all 171 mapped frameworks ↓Maps to 171 other frameworks
What is ISO/IEC 27004:2016 and who does it apply to?
ISO/IEC 27004:2016 is a compliance framework from International with 10 domains and 30 controls. Information technology - Security techniques - Information security management - Monitoring, measurement, analysis and evaluation. Provides guidance to assist organizations in evaluating information security performance and effectiveness of the ISMS. Supports ISO 27001 Clause 9.1 requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27004:2016 actually require?
ISO/IEC 27004:2016 has 30 controls organised across 10 domains. The largest domains are Annex Examples (6 controls), Clause 1-4: Introductory Clauses (4 controls), Clause 6: Characteristics of Monitoring, Measurement, Analysis and Evaluation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27004:2016 do I already cover?
ISO/IEC 27004:2016 maps to 171 other compliance frameworks. The top mapping partners are ISO 37001:2016 (7% coverage), WCAG 2.2 (7% coverage), W3C Verifiable Credentials (VC) Data Model 2.0 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27004:2016?
Start your ISO/IEC 27004:2016 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27004:2016 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required