Measure what you intend to change: 48 ISMS measures to ISO/IEC 27004
36 measurement examples from Annex B of ISO/IEC 27004:2016, plus 12 constructs for the 2022 controls — the formula for each, and what the number tells you. Free PDF.
Published on September 14, 2026
48 ISMS measures to ISO/IEC 27004
Clause 9.1 of ISO/IEC 27001 requires that you measure — not what. Annex B of ISO/IEC 27004:2016 shows, across 36 examples, what a measurement construct looks like. What it does not show is what goes wrong when you compute one. We worked through the 36 in our own wording, gave each a worked example, and added twelve constructs for the controls that did not exist in 2016. The result is a PDF, in German and English.
The gap between “we have KPIs” and “we measure”
In almost every audit there is a moment when the metrics slide comes out. Ten percentages, eight of them green. And then the question that tips it over: over what period, and what is in the denominator?
The answer is rarely a number. It is usually a sentence that begins with “the system pulls that automatically” and ends with the discovery that two runs of the same quarter give different results. At that point the metric is not wrong — it is unusable, because it cannot be settled. An auditor cannot reproduce it, and a board cannot decide anything on it.
This is exactly where ISO/IEC 27004 starts. It is also exactly where it stops.
What Annex B is — and what it is not
ISO/IEC 27004:2016 is the guidance to Clause 9.1: monitoring, measurement, analysis and evaluation. Its Annex B holds 36 measurement constructs, numbered B.2 to B.37, each a table with information need, measure, formula, target, evidence, frequency, responsible parties and reporting format.
Annex B is informative. It holds measurement examples, not mandatory metrics. What is required is Clause 9.1: that you measure — not that you measure these. Any sentence of the form “ISO requires 36 metrics” is false, and in an audit it costs credibility.
That is not a shortcoming of the standard but its purpose: it shows the shape of a measurement construct. What is then missing, for practice, is precisely what turns the shape into a number.
Four things a measurement example does not say
1. The time window
“Share of systems at current patch level” is not a measure until it is settled when you count: a cut-off date, a monthly average, or a rolling 30 days. The same estate yields three different percentages depending on the choice — all three correct, none of them comparable.
2. The counting unit
Numerator and denominator must count the same unit and be matched on the same identifier. An example from our own catalogue: if provider A delivers nine cloud services under a current contract and provider B delivers one under a stale contract, then provider-based contract currency is 1/2 = 50 %, while service-based currency is 9/10 = 90 %. Both numbers are legitimate. Neither is a reproduction of the other — and anyone who confuses them reports an improvement that did not happen.
3. The zero that is not a zero
“0 %” can mean three things: measured and genuinely zero; not applicable, because the denominator is empty; or simply not collected. In a management review those are three entirely different statements, and they must not land in the same cell. We keep them apart throughout as not_applicable, not_assessed and not_triggered.
4. Performance is not effectiveness
The standard separates performance measures in 7.2 from effectiveness measures in 7.3. The difference is not academic: “98 % of staff completed the training” is performance. Whether they act differently in a phishing test is effectiveness. A performance number at 100 % that is never followed by an effectiveness measure is a comfortable way of not knowing.
How the list is built
One page from the catalogue. The formula on the left, what the number tells you on the right, and in the first column the type of measure - performance, effectiveness or both. Seven such pages carry the 48.

A list page from the CWS ISMS Measurement Catalogue: measure type, the formula in one line, and what the number tells you.
Behind every line stand six fields a measure has to carry before it can carry a decision:
- Information need — the management question to be answered. Not the name of the metric.
- Measure and formula — numerator, denominator, time window and matching identifier, written out.
- Target logic — the standard’s target, or the explicit statement that the organisation sets it. Never an invented number.
- Evidence, source and frequency — where the number comes from, and how often it is collected and reported.
- Worked example — numbers, result, finding. If your own document cannot reproduce its own arithmetic, the discussion about metrics is over before it starts.
- Watch-out — the misreading this construct invites. For B.9 it is a quirk of the 2016 print itself.
The list prints the headline formula; where a construct carries further derived ratios, “plus n more” says exactly that. 48 measures, 48 lines - not 48 measures and 51 lines. If the numbers do not add up inside your own document, the discussion about metrics is over before it starts.
The 2016 gap: eleven controls with no example
Annex B dates from 2016 and is tied, through cross-reference table B.1, to the 2013 edition. Since then ISO/IEC 27002:2022 has introduced eleven controls that did not exist before — threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding — and ISO/IEC 27001:2022/Amd 1:2024 added the climate-relevance determination.
For these twelve subjects Annex B carries no explicitly mapped example. That is not silence: B.28 measures configuration compliance and B.27 log review — related, but not the same thing. So we built twelve constructs of our own on the same template and anchored each to a public measurement source: mostly the CIS Controls Assessment Specification v8.1, and where CIS is silent, NIST CSF 2.0, NIST SP 800-53 or ENISA.
These twelve are CyberWerkSuite constructs and are never presented as ISO examples. The source is printed in the header and the footer of every card — including the cases where our counting unit differs from the source’s. Where we have no public anchor at all, that is printed there too.
Three rules we hold ourselves to
- Separate provenance. Four levels, kept apart throughout: what the standard says; how we read it; which threshold we propose; and which figure is only a worked example. A catalogue that blends the four is not defensible in an audit.
- Do not reproduce the standard’s text. Construct numbers, titles and clause references are citations. Every description, every written-out formula and every worked example is our own wording. For the standard’s text you need your own copy of ISO/IEC 27004:2016.
- Date every statement about standard status. The status of a standard expires. So this catalogue carries the date it was checked wherever it makes such a claim — and the advice to check the ISO catalogue entry before relying on it.
Standard status: what is in force today
As checked on 13 September 2026: the second edition, ISO/IEC 27004:2016, is the edition in force; no amendment or corrigendum is published. A third edition is in development as ISO/IEC DIS 27004 and is not published. The draft lists among its changes the alignment with ISO/IEC 27001:2022 and references to ISO/IEC 27002:2022 in Annex B. This catalogue works from the 2016 edition in force and mentions the draft only as an indication of direction.
In practice: anyone setting up a measurement programme today sets it up on 2016. Anyone who builds it so that every measure carries a mapping line to ISO/IEC 27002:2022 — as this catalogue does — will have to check the mapping when the third edition appears, not rebuild the programme.
What is in the catalogue
Nine sections, grouped the way the standard groups them. The order is Annex B’s own; the section boundaries follow cross-reference table B.1. Section 9 is our extension and is marked as such.
| Section | Constructs |
|---|---|
| ISMS clauses 5-10 — Leadership, resources, risk, audit and improvement | 9 |
| A.7 Human resource security — Competence, awareness and behaviour | 5 |
| A.9 Access control — Authentication information and access rights | 3 |
| A.11 Physical and environmental security — Entry controls and equipment maintenance | 3 |
| A.12 / A.13 / A.17 Operations, networks and availability — Change, malware, logging, configuration, vulnerabilities | 9 |
| A.15 Supplier relationships — Security requirements in third-party agreements | 2 |
| A.16 Incident management — Resolution, trend and reporting | 3 |
| A.18 Compliance and independent review — Independent review and assessment coverage | 2 |
| CWS extension — extending the coverage of the 2016 examples — Twelve constructs built on the Annex B template | 12 |
Plus: a page on the data rule (time window, unique identifiers, empty denominators and exceptions), two pages on checking your own numbers, two pages on what has changed in ten years, and a page of the rules that apply before anything is published.
The two editions
| Edition | Extent | File |
|---|---|---|
| English | 16 pages · 4.4 MB | cws-isms-measurement-catalogue-48-en-v1.0.pdf |
| Deutsch | 16 pages · 4.4 MB | cws-isms-kennzahlenkatalog-48-de-v1.0.pdf |
Download the measurement catalogue as PDF
Free, no registration · PDF, 16 pages, 4.4 MB · Version 1.0, 13 September 2026
Both editions carry the same content and the same figures — down to the decimal separator.
What next?
ISMS_Suite_ — The catalogue is built into the tool: more than 300 assessable controls mapped to the 93 of Annex A, a living Statement of Applicability, generated policies, a risk engine — and the 48 constructs with target, frequency and owner, whose results feed the management review instead of a spreadsheet. See the ISO 27001 edition →
Certified ISMS Expert (CISE) — Forty hours of practical implementation applied to your own organisation: gap analysis, ISO 27005 risk work, the 93 controls and the Statement of Applicability — and the part most programmes leave out: Clause 9.1 measurement, internal audit and the management review. With an exam and a graded portfolio. See CyberWerkSuite →