A Backup That Reports Success Can Still Fail — Why ISO 27001 Demands Proof, Not Paperwork
Published on 10/03/2026 at 14:02 | Editorial boerse-global.de
Installing firewalls, endpoint agents and encryption is the easy part. Proving they actually work — and that gaps get closed rather than merely logged — is where many organisations stumble. That distinction sits at the heart of ISO/IEC 27001, the international information security management standard, whose 2022 revision sets binding rules for how security performance must be monitored, measured and evaluated.
What Section 9.1 Actually Requires
Under Section 9.1 of ISO/IEC 27001:2022, an organisation cannot simply assert that its security controls are effective. It must decide, in advance, what will be monitored and measured, which methods will be used, and when those measurements will take place. The standard also demands that responsibilities be pinned down: who carries out the measuring, and who reviews the results, and on what schedule.
Those methods have to produce results that are comparable and reproducible. Every measurement and every evaluation must be retained as documented information, so the management system's effectiveness can be demonstrated during internal and external audits alike.
Building Metrics That Mean Something
Translating that requirement into day-to-day operations calls for precisely defined security indicators. A workable system rests on a structured profile for each individual metric, covering:
- a clear definition and the underlying data source,
- the unit of measurement and the intended direction of travel,
- specific target values and warning thresholds set in advance,
- a binding collection rhythm and clearly assigned owners.
Specialists point out that pure activity metrics — the raw count of installed updates or closed tickets, for instance — reflect operational effort only, not the actual residual risk. What matters far more is measuring the quality of response and remediation.
That means tracking meaningful time spans until critical vulnerabilities are eliminated, adherence to agreed service windows, and high coverage when it comes to assigning IT assets to named individuals. Without clear ownership, measurements go nowhere: findings get recorded but never fixed in a targeted way.
Testing Recovery, Not Just Detecting Weaknesses
Measuring security also involves verifying fundamental protective mechanisms, not merely cataloguing flaws. Resilience is a prime example. A nightly backup job that returns a clean status message does not prove that the backed-up data would actually be readable and consistent in an emergency, or available within required recovery times.
Germany's BSI IT-Grundschutz makes the same point in module CON.3, requirement CON.3.A15, which obliges organisations to carry out regular restore tests. Only then can they demonstrate that backups can be recovered reliably and within a reasonable timeframe when it counts. Regular vulnerability analyses and controlled penetration tests round out the picture, providing the basis for spotting attack paths early.
How the Controls Are Organised
The practical foundation for security measures comes from ISO/IEC 27002:2022, whose catalogue of controls is incorporated into Annex A of ISO/IEC 27001. The controls were consolidated into 93 measures, divided across four thematic areas: organisational, people, physical and technological.
Organisations that align their management system with these requirements lay the groundwork for robust metrics — ones that satisfy the standard while making the security level measurably higher.
