ISMS Performance Evaluator
Description: After completing the course, participants will be able to demonstrate the following competences:
- Analytical Assessment – analyze and evaluate the effectiveness of existing ISMS controls.
- Measurement and Interpretation – define and use indicators to ensure compliance with requirements.
- Continuous Improvement – systematically introduce improvements based on measurement results, including proposing action plans.
- Strategic Alignment – ability to connect ISMS measurement results with the organization’s goals.
- Advisory Capability – competence in preparing reports and recommendations that support decision-making at the management level.
Previous skills/knowledge: Participants are expected to have the following basic knowledge:
- Basic understanding of information security principles (confidentiality, integrity, availability),
- Familiarity with ISO/IEC 27001 structure and key requirements (especially clause 9.1),
- Ability to interpret simple statistical indicators and percentages in business contexts.
Authorized Partners:
Teaching requirements: Trainers should meet the following requirements:
- Subject Matter Expertise – In-depth knowledge and practical experience with the ISO 27036 series (Parts 1–4), covering supplier relationships and information security throughout the supplier lifecycle.
- Certifications – Recommended certifications include ISO/IEC 27001 Lead Auditor or Implementer, with familiarity with ISO 27036:2021–2023.
- Training & Practical Experience – At least 2–3 years in managing information security in supplier relationships and delivering interactive workshops.
Objectives to achieve: The course aims to achieve the following objectives:
- Understand and apply the requirements of ISO/IEC 27001:2022 and ISO/IEC 27004:2016 for ISMS monitoring and measurement.
- Develop a structured approach to evaluating ISMS performance and interpreting results.
- Apply techniques for continuous improvement based on performance indicators.
- Learn to identify ineffective controls and propose alternative measures based on measurement results.
- Develop the ability to link performance metrics with the organization’s strategic objectives and reporting to top management.


