ISO 27001

Compliance KPIs for CISOs: 12 metrics worth reporting to the board

Boards want to know whether compliance is under control and getting better. These 12 metrics answer that, and they double as ISO 27001 clause 9.1 measurement.

Short answer

Useful compliance KPIs for CISOs measure readiness, operation and improvement: control coverage, evidence completeness, overdue access reviews, patching within SLA, open findings by age, corrective action closure time, training completion, supplier assessments current, incident response times, backup restore success, policy review currency and audit results. Each needs a definition, owner, source and target.

Key takeaways

  • Report a small, stable set of metrics, with trends rather than snapshots.
  • Each metric needs a definition, data source, owner and target.
  • Leading indicators (overdue reviews) matter more than lagging ones (incidents).
  • The same metrics evidence ISO 27001 clause 9.1 monitoring and measurement.

What boards actually want to know

Boards ask three questions: are we compliant enough to keep selling and stay out of trouble, are the important controls actually running, and is it getting better or worse? A short set of metrics, reported the same way every quarter, answers all three. ISO/IEC 27001 clause 9.1 asks for the same discipline: decide what to monitor and measure, how, when, and who analyses the results.

12 metrics that work

MetricDefinitionTypical target
Control coverageApplicable controls with an owner and evidence ÷ applicable controls≥ 95%
Evidence completenessEvidence requests approved on time ÷ requests due≥ 90%
Access reviews on timeSystems reviewed in the quarter ÷ systems in scope100%
Critical patches within SLACritical vulnerabilities fixed within SLA ÷ found≥ 95%
Open findings by ageAudit findings open > 90 daysTrending down
Corrective action closure timeMedian days from finding to verified closure< 60 days
Training completionStaff completed annual training ÷ staff in scope≥ 98%
Supplier assessments currentCritical suppliers assessed in last 12 months ÷ critical suppliers100%
Incident response timeMedian time from detection to containment for high-severity incidentsTrending down
Backup restore successSuccessful restore tests ÷ tests run100%
Policy review currencyPolicies reviewed within their cycle ÷ policies100%
External audit resultMajor and minor nonconformities at last auditZero major

Targets are illustrations. Set your own with leadership, and keep definitions stable so trends mean something.

Leading versus lagging

Incidents and audit findings tell you what already went wrong. Overdue access reviews, unpatched critical vulnerabilities and expired supplier assessments tell you what is about to. Put leading indicators first on the board slide, and use lagging ones to confirm whether they worked.

Making the metrics trustworthy

  • Define each metric once, with its formula and data source, and don't change it mid-year.
  • Pull numbers from systems of record (ticketing, IAM, scanners), not hand-built spreadsheets.
  • Name an owner who explains movements, not just reports numbers.
  • Show four to eight quarters of trend, not a single value.

How this supports ISO 27001

Clause 9.1 requires you to evaluate information security performance and ISMS effectiveness, keep evidence of the results, and use them in management review (9.3). A defined KPI set with owners and sources satisfies that, and ISO/IEC 27004 gives further guidance on designing measures.

Put this into practice on QULDEX

Frequently asked questions

How many compliance KPIs should a CISO report?

Usually 8 to 12. Fewer, stable metrics with trends are more useful to a board than a long list that changes every quarter.

Does ISO 27001 require KPIs?

Clause 9.1 requires you to decide what to monitor and measure and to evaluate performance. It doesn't name specific KPIs, but a defined metric set is the usual way to meet it.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO/IEC 27004:2016 Information security management: Monitoring, measurement, analysis and evaluation, ISO
  3. NIST SP 800-55 Vol. 1 Measurement Guide for Information Security, NIST